---
id: CVE-2026-98281
title: >-
  In the Linux kernel, the following vulnerability has been resolved:


  futex: Also allocate private hash on vfork()


  As Jann demonstrated, it is entirely feasible to access the mm through
  vfork().

  Therefore we need to allocate a private ha…
summary: >-
  In the Linux kernel, the following vulnerability has been resolved:


  futex: Also allocate private hash on vfork()


  As Jann demonstrated, it is entirely feasible to access the mm through
  vfork().

  Therefore we need to allocate a private ha…
severity: none
vendor: Linux
product: Linux
affected:
  - >-
    Linux >= 1dcd36420af2da5bd59306dba9caf78e3d248b1d <
    5468a4855b63b30156a79e5248e01bf1a2c18dd7
  - >-
    Linux >= ee9dce44362b2d8132c32964656ab6dff7dfbc6a <
    eecbafa8cabbc4d1482f6a5e2acc25a8f934681b
  - >-
    Linux >= ee9dce44362b2d8132c32964656ab6dff7dfbc6a <
    b61b6f95d6722ddbbbd09e689fa41b55fd36f9a5
  - Linux 974ac49a9a068b0591a59f65c63eb06579a13091
  - Linux >= 6.18.33 < 6.18.54
  - Linux >= 7.0.10 < 7.1
  - Linux 7.1
published: '2026-10-06'
updated: '2026-10-06'
sourceUpdated: '2026-10-06T09:18:18.040'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-98281'
references:
  - url: 'https://git.kernel.org/stable/c/5468a4855b63b30156a79e5248e01bf1a2c18dd7'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/b61b6f95d6722ddbbbd09e689fa41b55fd36f9a5'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
  - url: 'https://git.kernel.org/stable/c/eecbafa8cabbc4d1482f6a5e2acc25a8f934681b'
    label: 416baaa9-dc9f-4396-8d5f-8c081fb06d67
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-06T08:50:17.421Z'
---

## Overview

In the Linux kernel, the following vulnerability has been resolved:

futex: Also allocate private hash on vfork()

As Jann demonstrated, it is entirely feasible to access the mm through vfork().
Therefore we need to allocate a private hash on vfork() as well as any other
CLONE_VM user.

Specifically, it must be avoided to have (private) futex waiters before
allocating the private hash.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
