SB2026100806 - Improper initialization in Linux kernel need_futex_hash_allocate_default() in kernel/fork.c



SB2026100806 - Improper initialization in Linux kernel need_futex_hash_allocate_default() in kernel/fork.c

Published: October 8, 2026

Security Bulletin ID SB2026100806
CSH Severity
Low
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Code execution

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper initialization (CVE-ID: CVE-2026-98281)

CWE-ID: CWE-665 - Improper Initialization

CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to compromise system confidentiality, integrity, and availability.

The vulnerability exists due to improper initialization of the private futex hash in need_futex_hash_allocate_default() in kernel/fork.c when creating a vfork() child that shares its parent's memory address space. A local user can access the shared memory address space through vfork() with private futex waiters present before private hash allocation to compromise system confidentiality, integrity, and availability.


Remediation

Install update from vendor's website.