Improper initialization in Linux kernel - CVE-2026-98281

 

Improper initialization in Linux kernel - CVE-2026-98281

Published: October 8, 2026


Vulnerability identifier: #VU153956
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-98281
CWE-ID: CWE-665
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to compromise system confidentiality, integrity, and availability.

The vulnerability exists due to improper initialization of the private futex hash in need_futex_hash_allocate_default() in kernel/fork.c when creating a vfork() child that shares its parent's memory address space. A local user can access the shared memory address space through vfork() with private futex waiters present before private hash allocation to compromise system confidentiality, integrity, and availability.


Affected software

Linux kernel

How to mitigate CVE-2026-98281

Install security update from vendor's repository.

Linux kernel - update to 7.0 rc3

External References

Related Security Bulletins