In the Linux kernel 5.3.11, mounting a crafted btrfs image twice can cause an rwsem_down_write_slowpath use-after-free because (in rwsem_can_spin_on_owner in kernel/locking/rwsem.c) rwsem_owner_flags returns an already freed pointer,
3.11.0-12.194.2.0-16.194.2.0-17.214.2.0-19.234.3.0-1.104.3.0-2.114.3.0-5.164.3.0-6.174.3.0-7.184.4.0-2.166.11.0-8.86.5.0-9.95.3.0-18.195.3.0-24.265.4.0-9.124.13.0-16.196.8.0-31.315.13.0-19.195.13.0-1005.66.11.0-1004.4Exploitability
AV:LAC:LPR:HUI:NScope
S:UImpact
C:NI:NA:HCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H