extract_user_to_sg in lib/scatterlist.c in the Linux kernel before 6.4.12 fails to unpin pages in a certain situation, as demonstrated by a WARNING for try_grab_page. CREATE(Triage):(User=admin) CVE-2023-40791 (https://nvd.nist.gov/vuln/detail/CVE-2023-40791)