An issue was discovered in the Linux kernel before 4.18.7. In block/blk-core.c, there is an _blkdrain_queue() use-after-free because a certain error case is mishandled.
{ "urgency": "not yet assigned" }