In the Linux kernel, the following vulnerability has been resolved:dma-buf: insert memory barrier before updating num_fencessmp_store_mb() inserts memory barrier after storing operation.It is different with what the comment is originally aiming so Nullpointer dereference can be happened if memory update is reordered.
No PoCs from references.
- https://github.com/voidr3aper-anon/ghost
- https://github.com/w4zu/Debian_security