SB2026100806 - Improper initialization in Linux kernel need_futex_hash_allocate_default() in kernel/fork.c
Published: October 8, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper initialization (CVE-ID: CVE-2026-98281)
CWE-ID: CWE-665 - Improper Initialization
CVSSv4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to compromise system confidentiality, integrity, and availability.
The vulnerability exists due to improper initialization of the private futex hash in need_futex_hash_allocate_default() in kernel/fork.c when creating a vfork() child that shares its parent's memory address space. A local user can access the shared memory address space through vfork() with private futex waiters present before private hash allocation to compromise system confidentiality, integrity, and availability.
Remediation
Install update from vendor's website.