jbd2_journal_wait_updates in fs/jbd2/transaction.c in the Linux kernel before 5.17.1 has a use-after-free caused by a transaction_t race condition.
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.17.1
No PoCs found on GitHub currently.