In the Linux kernel, the following vulnerability has been resolved: dma-buf: insert memory barrier before updating num_fences smp_store_mb() inserts memory barrier after storing operation. It is different with what the comment is originally aiming so Null pointer dereference can be happened if memory update is reordered.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025070340-CVE-2025-38095-6596@gregkh/T