{"id":"CVE-2026-98281","summary":"futex: Also allocate private hash on vfork()","details":"In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Also allocate private hash on vfork()\n\nAs Jann demonstrated, it is entirely feasible to access the mm through vfork().\nTherefore we need to allocate a private hash on vfork() as well as any other\nCLONE_VM user.\n\nSpecifically, it must be avoided to have (private) futex waiters before\nallocating the private hash.","modified":"2026-10-08T02:52:56.021622685Z","published":"2026-10-06T08:45:40.719Z","database_specific":{"cna_assigner":"Linux","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98281.json"},"references":[{"type":"WEB","url":"https://git.kernel.org/stable/c/5468a4855b63b30156a79e5248e01bf1a2c18dd7"},{"type":"WEB","url":"https://git.kernel.org/stable/c/b61b6f95d6722ddbbbd09e689fa41b55fd36f9a5"},{"type":"WEB","url":"https://git.kernel.org/stable/c/eecbafa8cabbc4d1482f6a5e2acc25a8f934681b"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/98xxx/CVE-2026-98281.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-98281"},{"type":"PACKAGE","url":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"1dcd36420af2da5bd59306dba9caf78e3d248b1d"},{"fixed":"5468a4855b63b30156a79e5248e01bf1a2c18dd7"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"ee9dce44362b2d8132c32964656ab6dff7dfbc6a"},{"fixed":"eecbafa8cabbc4d1482f6a5e2acc25a8f934681b"},{"fixed":"b61b6f95d6722ddbbbd09e689fa41b55fd36f9a5"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"6.18.33"},{"fixed":"6.18.54"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"7.0.10"},{"fixed":"7.1"}]},{"type":"GIT","repo":"https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git","events":[{"introduced":"974ac49a9a068b0591a59f65c63eb06579a13091"}]}],"versions":["v6.18.53","v6.18.52","v6.18.51","v6.18.50","v6.18.49","v6.18.48","v6.18.47","v6.18.46","v6.18.45","v6.18.44","v6.18.43","v6.18.42","v6.18.41","v6.18.40","v6.18.39","v6.18.38","v6.18.37","v6.18.36","v6.18.35","v6.18.34","v6.18.33","v7.3-rc1","v7.2.7","v7.3-rc3","v7.2.6","v7.3-rc2","v7.2.5","v7.2.4","v7.2.3","v7.2.2","v7.2","v7.2.1","v7.2-rc1","v7.2-rc5","v7.2-rc7","v7.2-rc2","v7.2-rc6","v7.2-rc3","v7.2-rc4","v7.1","v7.1-rc7","v7.1-rc6","v7.1-rc4","v7.1-rc3","v7.1-rc2","v7.1-rc5","v7.0.14","v7.0.13","v7.0.12","v7.0.11","v7.0.10"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98281.json"}},{"package":{"name":"Kernel","ecosystem":"Linux"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.18.54"}]},{"type":"ECOSYSTEM","events":[{"introduced":"6.19.0"},{"fixed":"7.2.8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-98281.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}