CVE-2026-98281 PUBLISHED

futex: Also allocate private hash on vfork()

Assigner: Linux
Reserved: 25.09.2026 Published: 06.10.2026 Updated: 06.10.2026

In the Linux kernel, the following vulnerability has been resolved:

futex: Also allocate private hash on vfork()

As Jann demonstrated, it is entirely feasible to access the mm through vfork(). Therefore we need to allocate a private hash on vfork() as well as any other CLONE_VM user.

Specifically, it must be avoided to have (private) futex waiters before allocating the private hash.

Product Status

Vendor Linux
Product Linux
Versions Default: unaffected
  • affected from 1dcd36420af2da5bd59306dba9caf78e3d248b1d to 5468a4855b63b30156a79e5248e01bf1a2c18dd7 (excl.)
  • affected from ee9dce44362b2d8132c32964656ab6dff7dfbc6a to eecbafa8cabbc4d1482f6a5e2acc25a8f934681b (excl.)
  • affected from ee9dce44362b2d8132c32964656ab6dff7dfbc6a to b61b6f95d6722ddbbbd09e689fa41b55fd36f9a5 (excl.)
  • Version 974ac49a9a068b0591a59f65c63eb06579a13091 is affected
  • affected from 6.18.33 to 6.18.54 (excl.)
  • affected from 7.0.10 to 7.1 (excl.)
Vendor Linux
Product Linux
Versions Default: affected
  • Version 7.1 is affected
  • unaffected from 0 to 7.1 (excl.)
  • unaffected from 6.18.54 to 6.18.* (incl.)
  • unaffected from 7.2.8 to 7.2.* (incl.)
  • unaffected from 7.3-rc4 to * (incl.)

References