In the Linux kernel, the following vulnerability has been resolved: ring-buffer: Hold cpu_buffer::lock when resizing a subbuf Because, ring_buffer_subbuf_order_set() can clear cpu_buffer->free_page, hold cpu_buffer->lock to prevent races with ring_buffer_alloc_read_page() and ring_buffer_free_read_page().
https://git.kernel.org/stable/c/bf242baf58de03467f226c8e29554c9495dca7fc
https://git.kernel.org/stable/c/8a496aaa3da6e8d545896c2370c7e617cc931ae2
https://git.kernel.org/stable/c/6fcb0b745a0b80df62eae4a93ce52a2d061f4ac2
https://git.kernel.org/stable/c/24974bd0da1b47fd56c975533ead50abf754e74d