Nixpkgs security tracker

Login with GitHub

Suggestion detail

Dismissed
(max. allowed matches exceeded)
created 2 days, 5 hours ago Activity log
  • Created & dismissed (max. allowed matches exceeded) suggestion
kernel/fork: clear PF_BLOCK_TS in copy_process()

In the Linux kernel, the following vulnerability has been resolved: kernel/fork: clear PF_BLOCK_TS in copy_process() PF_BLOCK_TS is only set in blk_time_get_ns() when current->plug is non-NULL, and blk_finish_plug() clears it via __blk_flush_plug() before NULLing the plug pointer. copy_process() breaks the invariant by inheriting PF_BLOCK_TS from the parent while resetting the child's plug to NULL. Clear PF_BLOCK_TS alongside that assignment so callers can rely on "PF_BLOCK_TS set implies current->plug != NULL" and dereference current->plug unguarded.

Affected products

Linux
  • =<6.18.*
  • <6.9
  • <ee0801aceabdf583392477baf69a290b09448b8f
  • ==6.9
  • =<6.12.*
  • =<7.1.*
  • =<*
  • <77bba61a20f1b3d206f4f90e10a7bb3cd90b9619
  • <fd38b75c4b43295b10d69772a46d1c74dbd6fc81
  • <99e6c712cc300883b8cbf03347d5359ec1a4d6dd