Medium severity5.5NVD Advisory· Published Jul 24, 2026· Updated Aug 17, 2026
CVE-2026-64253
CVE-2026-64253
Description
In the Linux kernel, the following vulnerability has been resolved:
kernel/fork: clear PF_BLOCK_TS in copy_process()
PF_BLOCK_TS is only set in blk_time_get_ns() when current->plug is non-NULL, and blk_finish_plug() clears it via __blk_flush_plug() before NULLing the plug pointer. copy_process() breaks the invariant by inheriting PF_BLOCK_TS from the parent while resetting the child's plug to NULL.
Clear PF_BLOCK_TS alongside that assignment so callers can rely on "PF_BLOCK_TS set implies current->plug != NULL" and dereference current->plug unguarded.
Affected products
4- osv-coords2 versions
>= 6.9.0, < 6.12.95+ 1 more
- (no CPE)range: >= 6.9.0, < 6.12.95
- (no CPE)range: < 7.1.7-1.1
Patches
Vulnerability mechanics
References
4News mentions
1- Linux Kernel: 25 Vulnerabilities Across Subsystems Addressed in Coordinated July 2026 DisclosureVypr Intelligence · Jul 25, 2026