In the Linux kernel, the following vulnerability has been resolved:
fs/netfs/readcollect: add to next->prevdonated
If multiple subrequests donate data to the same "next" request
(depending on the subrequest completion order), each of them would
overwrite the prev_donated
field, causing data corruption and a
BUG() crash ("Can't donate prior to front").