In the Linux kernel, the following vulnerability has been resolved:
drm/vc4: Shut down BO cache timer before teardown
The BO cache timer callback schedules timework, and timework can rearm the timer through vc4bocachefreeold().
vc4bocache_destroy() deletes the timer and then cancels the work, which does not break that cycle: the work being cancelled can rearm the timer, and the timer then queues work again after teardown.
Use timershutdownsync() instead, so the timer cannot be rearmed and the cycle ends with cancelworksync().