CVE-2026-64253: kernel/fork: clear PF_BLOCK_TS in copy_process()
In the Linux kernel, the following vulnerability has been resolved:
kernel/fork: clear PFBLOCKTS in copyprocess()
PFBLOCKTS is only set in blktimegetns() when current->plug is non-NULL, and blkfinishplug() clears it via blkflushplug() before NULLing the plug pointer. copyprocess() breaks the invariant by inheriting PFBLOCKTS from the parent while resetting the child's plug to NULL.
Clear PFBLOCKTS alongside that assignment so callers can rely on "PFBLOCKTS set implies current->plug != NULL" and dereference current->plug unguarded.
Affected Software
Remediation
Event History
Frequently Asked Questions
Who can realistically trigger this issue?
The CVSS vector indicates local access and low privileges are required. The stated impact is availability only, with no confidentiality or integrity impact listed.
What runtime condition leads to the unsafe state?
A child created by fork can inherit PF_BLOCK_TS while its plug pointer is reset to NULL. Code that relies on PF_BLOCK_TS to mean that current->plug is valid can then dereference the NULL plug pointer.
What should be done if systems are affected?
A patch is available. The provided information does not identify a configuration-based workaround or other temporary mitigation.