CVE-2026-98281

Published: Ott 06, 2026 Last Modified: Ott 06, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

In the Linux kernel, the following vulnerability has been resolved:

futex: Also allocate private hash on vfork()

As Jann demonstrated, it is entirely feasible to access the mm through vfork().
Therefore we need to allocate a private hash on vfork() as well as any other
CLONE_VM user.

Specifically, it must be avoided to have (private) futex waiters before
allocating the private hash.

https://git.kernel.org/stable/c/5468a4855b63b30156a79e5248e01bf1a2c18dd7
https://git.kernel.org/stable/c/b61b6f95d6722ddbbbd09e689fa41b55fd36f9a5
https://git.kernel.org/stable/c/eecbafa8cabbc4d1482f6a5e2acc25a8f934681b