In the Linux kernel, the following vulnerability has been resolved: afs: Fix uncancelled rxrpc OOB message handler Fix AFS to cancel its OOB message processing (typically to respond to security challenges). Also move OOB message processing to afs_wq so that it's also waited for and make the OOB handler just return if the net namespace is no longer live.
https://git.kernel.org/stable/c/d14e96ddd616c8a9fff3b5bab3bf4af0cfc30ec4
https://git.kernel.org/stable/c/a4057e58b07005d0fe0491bdbf1868c1491909ee
https://git.kernel.org/stable/c/231414253b648b3518b56f09710b831945d6a2fc