kernel/fork: clear PF_BLOCK_TS in copy_process()
Summary
| CVE | CVE-2026-64253 |
| State | PUBLISHED |
| Assigner | Linux |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-24 16:16:55 UTC |
| Updated | 2026-07-24 16:16:55 UTC |
| Description | In the Linux kernel, the following vulnerability has been resolved:
kernel/fork: clear PF_BLOCK_TS in copy_process()
PF_BLOCK_TS is only set in blk_time_get_ns() when current->plug is
non-NULL, and blk_finish_plug() clears it via __blk_flush_plug()
before NULLing the plug pointer. copy_process() breaks the
invariant by inheriting PF_BLOCK_TS from the parent while resetting
the child's plug to NULL.
Clear PF_BLOCK_TS alongside that assignment so callers can rely on
"PF_BLOCK_TS set implies current->plug != NULL" and dereference
current->plug unguarded. |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|
| CNA |
Linux |
Linux |
affected 06b23f92af87a84d70881b2ecaa72e00f7838264 ee0801aceabdf583392477baf69a290b09448b8f git |
Not specified |
| CNA |
Linux |
Linux |
affected 06b23f92af87a84d70881b2ecaa72e00f7838264 99e6c712cc300883b8cbf03347d5359ec1a4d6dd git |
Not specified |
| CNA |
Linux |
Linux |
affected 06b23f92af87a84d70881b2ecaa72e00f7838264 77bba61a20f1b3d206f4f90e10a7bb3cd90b9619 git |
Not specified |
| CNA |
Linux |
Linux |
affected 06b23f92af87a84d70881b2ecaa72e00f7838264 fd38b75c4b43295b10d69772a46d1c74dbd6fc81 git |
Not specified |
| CNA |
Linux |
Linux |
affected 6.9 |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.9 semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.12.95 6.12.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 6.18.38 6.18.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.1.3 7.1.* semver |
Not specified |
| CNA |
Linux |
Linux |
unaffected 7.2-rc1 * original_commit_for_fix |
Not specified |
References
| Reference | Source | Link | Tags |
|---|
| git.kernel.org/stable/c/77bba61a20f1b3d206f4f90e10a7bb3cd90b9619 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/99e6c712cc300883b8cbf03347d5359ec1a4d6dd |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/fd38b75c4b43295b10d69772a46d1c74dbd6fc81 |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| git.kernel.org/stable/c/ee0801aceabdf583392477baf69a290b09448b8f |
416baaa9-dc9f-4396-8d5f-8c081fb06d67 |
git.kernel.org |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.