CVE-2026-98281 (GCVE-0-2026-98281)

Vulnerability from cvelistv5 – Published: 2026-10-06 08:45 – Updated: 2026-10-07 06:49
VLAI
Title
futex: Also allocate private hash on vfork()
Summary
In the Linux kernel, the following vulnerability has been resolved: futex: Also allocate private hash on vfork() As Jann demonstrated, it is entirely feasible to access the mm through vfork(). Therefore we need to allocate a private hash on vfork() as well as any other CLONE_VM user. Specifically, it must be avoided to have (private) futex waiters before allocating the private hash.
Impacted products
Vendor Product Version
Linux Linux Affected: 1dcd36420af2da5bd59306dba9caf78e3d248b1d , < 5468a4855b63b30156a79e5248e01bf1a2c18dd7 (git)
Affected: ee9dce44362b2d8132c32964656ab6dff7dfbc6a , < eecbafa8cabbc4d1482f6a5e2acc25a8f934681b (git)
Affected: ee9dce44362b2d8132c32964656ab6dff7dfbc6a , < b61b6f95d6722ddbbbd09e689fa41b55fd36f9a5 (git)
Affected: 974ac49a9a068b0591a59f65c63eb06579a13091 (git)
Affected: 6.18.33 , < 6.18.54 (semver)
Affected: 7.0.10 , < 7.1 (semver)
Create a notification for this product.
Linux Linux Affected: 7.1
Unaffected: 0 , < 7.1 (semver)
Unaffected: 6.18.54 , ≤ 6.18.* (semver)
Unaffected: 7.2.8 , ≤ 7.2.* (semver)
Unaffected: 7.3-rc4 , ≤ * (original_commit_for_fix)
Create a notification for this product.
Show details on NVD website

{
  "containers": {
    "cna": {
      "affected": [
        {
          "defaultStatus": "unaffected",
          "product": "Linux",
          "programFiles": [
            "kernel/fork.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "lessThan": "5468a4855b63b30156a79e5248e01bf1a2c18dd7",
              "status": "affected",
              "version": "1dcd36420af2da5bd59306dba9caf78e3d248b1d",
              "versionType": "git"
            },
            {
              "lessThan": "eecbafa8cabbc4d1482f6a5e2acc25a8f934681b",
              "status": "affected",
              "version": "ee9dce44362b2d8132c32964656ab6dff7dfbc6a",
              "versionType": "git"
            },
            {
              "lessThan": "b61b6f95d6722ddbbbd09e689fa41b55fd36f9a5",
              "status": "affected",
              "version": "ee9dce44362b2d8132c32964656ab6dff7dfbc6a",
              "versionType": "git"
            },
            {
              "status": "affected",
              "version": "974ac49a9a068b0591a59f65c63eb06579a13091",
              "versionType": "git"
            },
            {
              "lessThan": "6.18.54",
              "status": "affected",
              "version": "6.18.33",
              "versionType": "semver"
            },
            {
              "lessThan": "7.1",
              "status": "affected",
              "version": "7.0.10",
              "versionType": "semver"
            }
          ]
        },
        {
          "defaultStatus": "affected",
          "product": "Linux",
          "programFiles": [
            "kernel/fork.c"
          ],
          "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
          "vendor": "Linux",
          "versions": [
            {
              "status": "affected",
              "version": "7.1"
            },
            {
              "lessThan": "7.1",
              "status": "unaffected",
              "version": "0",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "6.18.*",
              "status": "unaffected",
              "version": "6.18.54",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "7.2.*",
              "status": "unaffected",
              "version": "7.2.8",
              "versionType": "semver"
            },
            {
              "lessThanOrEqual": "*",
              "status": "unaffected",
              "version": "7.3-rc4",
              "versionType": "original_commit_for_fix"
            }
          ]
        }
      ],
      "cpeApplicability": [
        {
          "nodes": [
            {
              "cpeMatch": [
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "6.18.54",
                  "versionStartIncluding": "6.18.33",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.2.8",
                  "versionStartIncluding": "7.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionEndExcluding": "7.3-rc4",
                  "versionStartIncluding": "7.1",
                  "vulnerable": true
                },
                {
                  "criteria": "cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*",
                  "versionStartIncluding": "7.0.10",
                  "vulnerable": true
                }
              ],
              "negate": false,
              "operator": "OR"
            }
          ]
        }
      ],
      "descriptions": [
        {
          "lang": "en",
          "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Also allocate private hash on vfork()\n\nAs Jann demonstrated, it is entirely feasible to access the mm through vfork().\nTherefore we need to allocate a private hash on vfork() as well as any other\nCLONE_VM user.\n\nSpecifically, it must be avoided to have (private) futex waiters before\nallocating the private hash."
        }
      ],
      "metrics": [
        {
          "cvssV3_1": {
            "baseScore": 7.8,
            "baseSeverity": "HIGH",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "scenarios": [
            {
              "lang": "en",
              "value": "AV:L - The trigger is a local process calling vfork()/clone3(CLONE_VM|CLONE_VFORK) in kernel_clone()/copy_process(), where need_futex_hash_allocate_default() skipped the private hash, followed by futex() syscalls on the shared mm. No remote peer supplies any input.\nAC:L - The attacker owns every task involved: the vfork parent (killed through its TASK_KILLABLE wait_for_vfork_done, so its futex exit path runs on the shared mm) and the vfork child, which creates a thread to publish the first private hash. Both sides of the race are under attacker control, so it can be retried at will.\nPR:L - vfork, clone, futex(FUTEX_WAIT/LOCK_PI), robust lists and kill() all work for an ordinary unprivileged user with no capability checks. The hash allocation in futex_hash_allocate_default() has no privilege gate either.\nUI:N - The attacker\u0027s own processes create the shared-mm state and the futex operations. No other user has to do anything.\nS:U - The damaged objects are kernel futex state (mm-\u003efutex.phash, hash buckets, pi_state) inside the same kernel security authority. No guest/host or IOMMU boundary is crossed.\nC:H - __futex_pivot_hash() leaves waiters queued in the global hash when the private hash is first published, so later PI/requeue operations take a different bucket lock. Futex PI state handled under two different bucket locks is the classic futex use-after-free pattern, and the earlier bug from this same assumption was a KASAN use-after-free, so kernel memory disclosure is plausible.\nI:H - A freed pi_state or private-hash reference that the attacker can reallocate gives a kernel heap write primitive, as in earlier futex PI use-after-free exploits, so local privilege escalation is possible.\nA:H - Waiters stranded in the global hash miss every later wake that goes to the private bucket, which hangs the affected tasks. The pi_state/reference corruption from inconsistent bucket locking can cause a KASAN splat or kernel oops."
            }
          ]
        }
      ],
      "providerMetadata": {
        "dateUpdated": "2026-10-07T06:49:52.329Z",
        "orgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "shortName": "Linux"
      },
      "references": [
        {
          "url": "https://git.kernel.org/stable/c/5468a4855b63b30156a79e5248e01bf1a2c18dd7"
        },
        {
          "url": "https://git.kernel.org/stable/c/eecbafa8cabbc4d1482f6a5e2acc25a8f934681b"
        },
        {
          "url": "https://git.kernel.org/stable/c/b61b6f95d6722ddbbbd09e689fa41b55fd36f9a5"
        }
      ],
      "title": "futex: Also allocate private hash on vfork()",
      "x_generator": {
        "engine": "bippy-1.2.0"
      }
    }
  },
  "cveMetadata": {
    "assignerOrgId": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
    "assignerShortName": "Linux",
    "cveId": "CVE-2026-98281",
    "datePublished": "2026-10-06T08:45:40.719Z",
    "dateReserved": "2026-09-25T10:25:14.335Z",
    "dateUpdated": "2026-10-07T06:49:52.329Z",
    "state": "PUBLISHED"
  },
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "vulnerability-lookup:meta": {
    "epss": {
      "cve": "CVE-2026-98281",
      "date": "2026-10-08",
      "epss": "0.00136",
      "percentile": "0.02628"
    },
    "nvd": {
      "cve": {
        "affected": [
          {
            "affectedData": [
              {
                "defaultStatus": "unaffected",
                "product": "Linux",
                "programFiles": [
                  "kernel/fork.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "lessThan": "5468a4855b63b30156a79e5248e01bf1a2c18dd7",
                    "status": "affected",
                    "version": "1dcd36420af2da5bd59306dba9caf78e3d248b1d",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "eecbafa8cabbc4d1482f6a5e2acc25a8f934681b",
                    "status": "affected",
                    "version": "ee9dce44362b2d8132c32964656ab6dff7dfbc6a",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "b61b6f95d6722ddbbbd09e689fa41b55fd36f9a5",
                    "status": "affected",
                    "version": "ee9dce44362b2d8132c32964656ab6dff7dfbc6a",
                    "versionType": "git"
                  },
                  {
                    "status": "affected",
                    "version": "974ac49a9a068b0591a59f65c63eb06579a13091",
                    "versionType": "git"
                  },
                  {
                    "lessThan": "6.18.54",
                    "status": "affected",
                    "version": "6.18.33",
                    "versionType": "semver"
                  },
                  {
                    "lessThan": "7.1",
                    "status": "affected",
                    "version": "7.0.10",
                    "versionType": "semver"
                  }
                ]
              },
              {
                "defaultStatus": "affected",
                "product": "Linux",
                "programFiles": [
                  "kernel/fork.c"
                ],
                "repo": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git",
                "vendor": "Linux",
                "versions": [
                  {
                    "status": "affected",
                    "version": "7.1"
                  },
                  {
                    "lessThan": "7.1",
                    "status": "unaffected",
                    "version": "0",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "6.18.*",
                    "status": "unaffected",
                    "version": "6.18.54",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "7.2.*",
                    "status": "unaffected",
                    "version": "7.2.8",
                    "versionType": "semver"
                  },
                  {
                    "lessThanOrEqual": "*",
                    "status": "unaffected",
                    "version": "7.3-rc4",
                    "versionType": "original_commit_for_fix"
                  }
                ]
              }
            ],
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67"
          }
        ],
        "cveTags": [],
        "descriptions": [
          {
            "lang": "en",
            "value": "In the Linux kernel, the following vulnerability has been resolved:\n\nfutex: Also allocate private hash on vfork()\n\nAs Jann demonstrated, it is entirely feasible to access the mm through vfork().\nTherefore we need to allocate a private hash on vfork() as well as any other\nCLONE_VM user.\n\nSpecifically, it must be avoided to have (private) futex waiters before\nallocating the private hash."
          }
        ],
        "id": "CVE-2026-98281",
        "lastModified": "2026-10-07T07:17:07.800",
        "metrics": {
          "cvssMetricV31": [
            {
              "cvssData": {
                "attackComplexity": "LOW",
                "attackVector": "LOCAL",
                "availabilityImpact": "HIGH",
                "baseScore": 7.8,
                "baseSeverity": "HIGH",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "HIGH",
                "privilegesRequired": "LOW",
                "scope": "UNCHANGED",
                "userInteraction": "NONE",
                "vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              },
              "exploitabilityScore": 1.8,
              "impactScore": 5.9,
              "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
              "type": "Secondary"
            }
          ]
        },
        "published": "2026-10-06T09:18:18.040",
        "references": [
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/5468a4855b63b30156a79e5248e01bf1a2c18dd7"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/b61b6f95d6722ddbbbd09e689fa41b55fd36f9a5"
          },
          {
            "source": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
            "url": "https://git.kernel.org/stable/c/eecbafa8cabbc4d1482f6a5e2acc25a8f934681b"
          }
        ],
        "sourceIdentifier": "416baaa9-dc9f-4396-8d5f-8c081fb06d67",
        "vulnStatus": "Received"
      }
    },
    "suse_vex": {
      "aggregate_severity": "important",
      "current_release_date": "2026-10-08T16:48:41Z",
      "cve": "CVE-2026-98281",
      "id": "CVE-2026-98281",
      "initial_release_date": "2026-10-08T16:48:41Z",
      "product_status:known_not_affected": "347",
      "source": "SUSE CSAF VEX",
      "status": "interim",
      "title": "SUSE CVE CVE-2026-98281",
      "url": "https://ftp.suse.com/pub/projects/security/csaf-vex/cve-2026-98281.json",
      "version": "2"
    }
  }
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…