In the Linux kernel, the following vulnerability has been resolved: scsi: message: mptlan: Fix use after free bug in mptlanremove() due to race condition mptlanprobe() calls mptregisterlandevice() which initializes the &priv->postbucketstask workqueue. A call to mptlanwakepostbucketstask() will subsequently start the work. During driver unload in mptlanremove() the following race may occur: CPU0 CPU1 |mptlanpostreceivebucketswork() mptlanremove() | freenetdev() | kfree(dev); | | | dev->mtu | //use Fix this by finishing the work prior to cleaning up in mptlan_remove(). [mkp: we really should remove mptlan instead of attempting to fix it]