On Tue, Oct 18, 2022 at 05:05:09PM +0800, Yu Kuai wrote: > 2) run the cmd: > > dmsetup create test1 --table "0 100000 linear /dev/sda 0" & > sleep 1 > echo 1 > /sys/block/sda/device/delete > > And the follwing uaf is triggered: Yes, for that we also need to clear the pointer and unregister all holder in del_gedisk (or even better move this mess to dm :()