When issuing task management or configuration commands to a target device
via userland IOCTL, the driver temporarily blocks host I/O to that target.
If the command fails or times out, the error unwinding path decremented
the I/O blocking counter using the originally resolved target pointer.
However, management command timeouts can be lengthy. If the target device
was removed or deleted while the IOCTL was waiting for completion, the
original target structure could have been freed before the command timed
out. Decrementing the counter through the stale pointer resulted in a
use-after-free.
Safely re-lookup the target device by its hardware handle from the active
device list before modifying the counter. If the device was already
removed, the stale pointer dereference is safely skipped.