---
id: CVE-2026-52973
title: |-
  In the Linux kernel, the following vulnerability has been resolved:

  futex: Drop CLONE_THREAD requirement for private default hash alloc

  Currently need_futex_hash_allocate_default() depends on strict pthread
  semantics, abusing CLONE_THR…
summary: |-
  In the Linux kernel, the following vulnerability has been resolved:

  futex: Drop CLONE_THREAD requirement for private default hash alloc

  Currently need_futex_hash_allocate_default() depends on strict pthread
  semantics, abusing CLONE_THR…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-825
published: '2026-06-24'
updated: '2026-07-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-52973'
references:
  - url: 'https://git.kernel.org/stable/c/1dcd36420af2da5bd59306dba9caf78e3d248b1d'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/974ac49a9a068b0591a59f65c63eb06579a13091'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/ee9dce44362b2d8132c32964656ab6dff7dfbc6a'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://access.redhat.com/security/cve/CVE-2026-52973'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2492413'
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-52973.json
    label: 0b0ca135-0b70-47e7-9f44-1890c2a1c46c
tags:
  - nvd
epss: 0.00184
epssPercentile: 0.07107
ingestedAt: '2026-07-11T13:13:25.118Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

futex: Drop CLONE_THREAD requirement for private default hash alloc

Currently need_futex_hash_allocate_default() depends on strict pthread
semantics, abusing CLONE_THREAD.  This breaks the non-concurrency
assumptions when doing the mm->futex_ref pcpu allocations, leading to
bugs[0] when sharing the mm in other ways; ie:

    BUG: KASAN: slab-use-after-free in futex_hash_put

... where the +1 bias can end up on a percpu counter that mm->futex_ref
no longer points at.

Loosen the check to cover any CLONE_VM clone, except vfork().  Excluding
vfork keeps the existing paths untouched (no overhead), and we can't
race in the first place: either the parent is suspended and the child
runs alone, or mm->futex_ref is already allocated from an earlier
CLONE_VM.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
