In the Linux kernel, the following vulnerability has been resolved:
HID: sensor: custom: Fix use-after-free in enable_sensor
enablesensorstore() can call setpowerreportstate(), which dereferences sensorinst->powerstate and sensorinst->reportstate. These pointers refer to entries in sensorinst->fields.
Create the field attributes before exposing the enablesensor sysfs attribute, so enablesensor cannot be accessed before the state it depends on has been initialized.
On remove, delete enablesensor before freeing the field attributes, so a concurrent sysfs write cannot dereference freed memory through powerstate or report_state.