In the Linux kernel, the following vulnerability has been resolved: spi: atcspi200: fix use-after-free when driver unbind DMA resource is initialized after SPI controller registration. So when driver unbind, this can trigger a use-after-free when DMA is torn down while the controller is still alive and triggers DMA transfers.
https://git.kernel.org/stable/c/af6a34c41683067a314d2b58b39edecb2e5e4ac6
https://git.kernel.org/stable/c/565bdf45125a05aa8f622f58f598283f46ba43f4