Improper initialization in Linux kernel - CVE-2026-98281
Published: October 8, 2026
Vulnerability details
The vulnerability allows a local user to compromise system confidentiality, integrity, and availability.
The vulnerability exists due to improper initialization of the private futex hash in need_futex_hash_allocate_default() in kernel/fork.c when creating a vfork() child that shares its parent's memory address space. A local user can access the shared memory address space through vfork() with private futex waiters present before private hash allocation to compromise system confidentiality, integrity, and availability.