In the Linux kernel, the following vulnerability has been resolved:
dax: make sure inodes are flushed before destroy cache
A bug can be triggered by following command
$ modprobe ndpmem && modprobe -r ndpmem
[ 10.060014] BUG daxcache (Not tainted): Objects remaining in daxcache on _kmemcacheshutdown() [ 10.060938] Slab 0x0000000085b729ac objects=9 used=1 fp=0x000000004f5ae469 flags=0x200000000010200(slab|head|node) [ 10.062433] Call Trace: [ 10.062673] dumpstacklvl+0x34/0x44 [ 10.062865] slaberr+0x90/0xd0 [ 10.063619] _kmemcacheshutdown+0x13b/0x2f0 [ 10.063848] kmemcachedestroy+0x4a/0x110 [ 10.064058] _x64sysdelete_module+0x265/0x300
This is caused by daxfsexit() not flushing inodes before destroy cache. To fix this issue, call rcu_barrier() before destroy cache.