Back to overview

CVE-2026-64253

Description
In the Linux kernel, the following vulnerability has been resolved: kernel/fork: clear PF_BLOCK_TS in copy_process() PF_BLOCK_TS is only set in blk_time_get_ns() when current->plug is non-NULL, and blk_finish_plug() clears it via __blk_flush_plug() before NULLing the plug pointer. copy_process() breaks the invariant by inheriting PF_BLOCK_TS from the parent while resetting the child's plug to NULL. Clear PF_BLOCK_TS alongside that assignment so callers can rely on "PF_BLOCK_TS set implies current->plug != NULL" and dereference current->plug unguarded.

Metadata

CVE ID
CVE-2026-64253
State
PUBLISHED
Assigner
Linux
Reserved
2026-07-19 15:36 UTC
Published
2026-07-24 15:31 UTC
Last updated
2026-07-24 15:31 UTC
Vendor / Product
Linux / Linux
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (2)
VendorProductPlatformVersions
Linux Linux 06b23f92af87a84d70881b2ecaa72e00f7838264 < ee0801aceabdf583392477baf69a290b09448b8f, 06b23f92af87a84d70881b2ecaa72e00f7838264 < 99e6c712cc300883b8cbf03347d5359ec1a4d6dd, 06b23f92af87a84d70881b2ecaa72e00f7838264 < 77bba61a20f1b3d206f4f90e10a7bb3cd90b9619, 06b23f92af87a84d70881b2ecaa72e00f7838264 < fd38b75c4b43295b10d69772a46d1c74dbd6fc81
Linux Linux 6.9, 0 < 6.9, 6.12.95 ≤ 6.12.*, 6.18.38 ≤ 6.18.* …
Back to overview