In the Linux kernel, the following vulnerability has been resolved: nbd: fix race between timeout and normal completion If request timetout is handled by nbd_requeue_cmd(), normal completion has to be stopped for avoiding to complete this requeued request, other use-after-free can be triggered. Fix the race by clearing NBD_CMD_INFLIGHT in nbd_requeue_cmd(), meantime make sure that cmd->lock is grabbed for clearing the flag and the requeue.
| Product | Vendor | Version |
|---|---|---|
| Linux | Linux | 12.5.0 |
| Linux | Linux | 14.1.0 |
| Linux | Linux | < 6.3.9600.22620 |
| Linux | Linux | < 10.0.25398.1665 |