In the Linux kernel, the following vulnerability has been resolved: drm/amdkfd: fix UAF race in destroy_queue_cpsch wait_on_destroy_queue() drops locks to wait for queue resume, allowing a concurrent destroy to free the queue. Use is_being_destroyed flag to serialize destruction.
https://git.kernel.org/stable/c/d98c8032c29944e1e572e1f49a0613d364fece0f
https://git.kernel.org/stable/c/ac081deaf16a639ea7dff2f285fe421a33c1ade0
https://git.kernel.org/stable/c/41144829f4645c2bd4cb501d34d253858f750c0a