In the Linux kernel, the following vulnerability has been resolved: smb: client: let send_done handle a completion without IB_SEND_SIGNALED With smbdirect_send_batch processing we likely have requests without IB_SEND_SIGNALED, which will be destroyed in the final request that has IB_SEND_SIGNALED set. If the connection is broken all requests are signaled even without explicit IB_SEND_SIGNALED.
https://git.kernel.org/stable/c/cf74fcdc43b322b6188a0750b5ee79e38be6d078
https://git.kernel.org/stable/c/86d9742c3f7ed7eba677517c80b4597822750e65
https://git.kernel.org/stable/c/16c8be3d55441287ddd334e25df4cc376450dec9