In the Linux kernel, the following vulnerability has been resolved:
vt: stabilize tty reference in kbdkeycode with ttyportttyget
kbdkeycode() reads vc->port.tty without acquiring a tty reference, racing against conshutdown() which clears port.tty under a different lock. Use ttyportttyget()/ttykref_put() to hold a proper reference for the duration the tty pointer is needed.