{"id":"CVE-2026-71226","published":"2026-08-05T13:24:47.223","lastModified":"2026-08-10T09:17:23.783","description":"Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.","cvssScore":7.3,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","cwes":["CWE-416"],"vendors":[],"products":[],"references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-71226","tags":[]},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2462114","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows memory corruption via uncanceled AIO requests on error, potentially leading to kernel writes into caller-owned buffers.","exploitability":"Exploitation requires specific conditions where AIO requests are not canceled before errors occur; this is considered moderately difficult.","blast_radius":"If exploited, the impact could be high, as it may lead to arbitrary code execution or data corruption in the kernel space.","remediation":"Update to the latest version of libkcapi that addresses this vulnerability.","tags":["memory-corruption","kernel","aio","high-impact"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T07:00:56.659Z"}}