yocto ▾
›
scarthgap ▾
›
vulnerability
›
CVE-2026-71226
Component Overview
Vulnerability Overview
Name
CVE-2026-71226
Source
NVD (
link
)
Debian (
link
)
Description
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
CWEs
CWE-416
Published Date
Aug 5, 2026
Updated Date
Aug 19, 2026
Workaround
-
Advisories
https://access.redhat.com/security/cve/CVE-2026-71226
Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2462114
Issue Tracking
Analysis
#
Affected Component
Analysis
libkcapi
Exploitable
Vulnerability Ratings
#
7.3
CVSSv31
7.3
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
libkcapi
yocto
kirkstone
1.4.0
Exploitable
libkcapi
yocto
master
1.5.1
Not Affected