Memory Corruption Vulnerability in libkcapi AIO Path
CVE-2026-71226
7.3HIGH
What is CVE-2026-71226?
A memory corruption vulnerability exists within libkcapi's one-shot Asynchronous Input/Output (AIO) path. This issue arises when the AIO mechanism can signal an error before all submitted Input/Output Control Blocks (IOCBs) are processed. As a result, this can lead to unintended kernel-level writes into memory buffers allocated by the calling process, potentially compromising the integrity of the affected system. It is crucial to apply updates and patches provided by the vendor to mitigate this risk and enhance overall system security.
References
CVSS V3.1
Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This issue was discovered by Found by AISLE in partnership with Red Hat.