In the Linux kernel, the following vulnerability has been resolved:
thermal: core: Free tzp copy along with the thermal zone
The object pointed to by tz->tzp may still be accessed after being freed in thermalzonedevice_unregister(), so move the freeing of it to the point after the removal completion has been completed at which it cannot be accessed any more.