In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix potential kgd_mem UAFs kgd_mem pointers returned by kfd_process_device_translate_handle are only guaranteed to be valid while p->mutex is held. As soon as the mutex is unlocked, another thread can free the BO.
https://git.kernel.org/stable/c/9da050b0d9e04439d225a2ec3044af70cdfb3933
https://git.kernel.org/stable/c/5ca14fb5552ac13a2402d306c0bd2379a71610ff
https://git.kernel.org/stable/c/5045360f3bb62ccd4f87202e33489f71f8bbc3fc