In the Linux kernel, the following vulnerability has been resolved: netfs: clear PG_private_2 on copy-to-cache append failure netfs_pgpriv2_copy_to_cache() marks the folio with PG_private_2 before netfs_pgpriv2_copy_folio() appends it to the copy-to-cache rolling buffer. If the append fails, the folio is not queued for cache writeback, so the PG_private_2 state and its reference must be released immediately.
https://git.kernel.org/stable/c/a81fc9266e1c5fef9ccf675a9b44b2f4ab464923
https://git.kernel.org/stable/c/627826ef4208042b0470d1a3fdb729ce35471a0d
https://git.kernel.org/stable/c/614b7f4bfcf665a751ae89ff9ae336a1b2d5af4e