In the Linux kernel, the following vulnerability has been resolved: fs/netfs/read_collect: add to next->prev_donated If multiple subrequests donate data to the same "next" request (depending on the subrequest completion order), each of them would overwrite the `prev_donated` field, causing data corruption and a BUG() crash ("Can't donate prior to front").
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025040254-CVE-2025-21988-e048@gregkh/T