Overview
What is CVE-2026-71226?
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.
Vulnerability intelligence
CVE-2026-71226 and is rated High severity with a CVSS score of 7.3. It is not in the current CISA KEV record we collected. That does not prove exploitation has not occurred.
Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one-shot AIO path can return an error before all submitted IOCBs are drained, allowing later kernel writes into caller-owned output buffers.