In arch/x86/lib/insn-eval.c in the Linux kernel before 5.1.9, there is a use-after-free for access to an LDT entry because of a race condition between modify_ldt() and a #BR exception for an MPX bounds violation.
4.15.0-1047.49~16.04.14.15.0-1055.604.15.0-1040.42~16.04.14.15.0-58.64~16.04.14.15.0-1021.23~16.04.14.15.0-58.644.15.0-1047.495.0.0-1014.14~18.04.14.15.0-1040.424.15.0-1040.42Exploitability
AV:LAC:HPR:LUI:NScope
S:UImpact
C:HI:HA:HCVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H