Commit d8bdcb08d0eb fixed a problem in kqueue_fork_copy_knote() where we
did not skip over marker knotes when copying. However, that fix was not
sufficient: we bump the influx counter and check for a marker after
dropping the kqueue lock. So, if multiple threads in a process are
forking concurrently, kqueue_fork_copy_list() may mark a marker as
in-flux and drop the lock; if the marker owner then frees the marker,
the first thread will decrement the in-flux counter of a freed knotes.
This use-after-free can be exploited, at least prior to commit
d8bdcb08d0eb, which (inadvertently) makes exploitation more challenging.
Reported by: Reo Shiseki