Race condition in the get_task_ioprio function in block/ioprio.c in the Linux kernel before 4.6.6 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted ioprio_get system call.
No PoCs from references.
- https://github.com/andrewwebber/kate
- https://github.com/wcventure/PERIOD