In the Linux kernel, the following vulnerability has been resolved:
spi: tegra20-slink: fix UAF in tegraslinkremove()
After calling spiunregistermaster(), the refcount of master will be decrease to 0, and it will be freed in spicontrollerrelease(), the device data also will be freed, so it will lead a UAF when using 'tspi'. To fix this, get the master before unregister and put it when finish using it.