{"id":"CVE-2026-71226","summary":"Libkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio path","details":"Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.","modified":"2026-09-16T03:31:06.077243860Z","published":"2026-08-05T12:37:17.360Z","related":["ALSA-2026:67265","ALSA-2026:67266","ALSA-2026:67267"],"database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71226.json"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://catalog.redhat.com/software/containers/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:56985"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:67265"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:67266"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:67267"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-71226"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/71xxx/CVE-2026-71226.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-71226"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2462114"},{"type":"PACKAGE","url":"https://github.com/smuellerDD/libkcapi"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/smuellerdd/libkcapi","events":[{"introduced":"5ba1fbe1b5ff967c398e4dffab083d543809195c"},{"fixed":"df40ea48ecbf1afc6d3efa5494673fa73bd40826"}],"database_specific":{"extracted_events":[{"introduced":"0.12.0"},{"fixed":"1.5.1"}],"source":"AFFECTED_FIELD"}}],"versions":["v1.5.0","v1.4.0","v1.3.1","v1.3.0","v1.2.1","v1.2.0","v1.1.5","v1.1.4","v1.1.3","v1.1.2","v1.1.1","v1.1.0","v1.0.3","v1.0.2","v1.0.1","v1.0.0","v0.14.0","v0.13.0","v0.12.0"],"database_specific":{"source":"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-71226.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H"}]}