Use After Free Affecting smuellerDD/libkcapi package, versions [,1.5.1)


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.12% (3rd percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Use After Free vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-UNMANAGED-SMUELLERDDLIBKCAPI-18600604
  • published9 Aug 2026
  • disclosed5 Aug 2026
  • creditUnknown

Introduced: 5 Aug 2026

NewCVE-2026-71226  (opens in a new tab)
CWE-416  (opens in a new tab)

How to fix?

Upgrade smuellerDD/libkcapi to version 1.5.1 or higher.

Overview

Affected versions of this package are vulnerable to Use After Free in the one-shot Asynchronous I/O process when the KCAPI_INIT_AIO flag is used. An attacker can cause memory corruption by triggering an error after submitting I/O Control Blocks, then freeing or reusing output buffers before all kernel completions are processed, which may result in delayed kernel writes into reallocated or freed memory. This is only exploitable if the application is configured to use the opt-in AIO setup with the KCAPI_INIT_AIO flag enabled.

Workaround

This vulnerability can be mitigated by avoiding initialization with the KCAPI_INIT_AIO flag and preferring synchronous interfaces, or by ensuring that outiov buffers are not freed or reused until all kernel completions have finished.

CVSS Base Scores

version 4.0
version 3.1