In the Linux kernel, the following vulnerability has been resolved: Revert "nbd: fix possible overflow on 'first_minor' in nbd_dev_add()" This reverts commit 6d35d04a9e18990040e87d2bbf72689252669d54. Both Gabriel and Borislav report that this commit casues a regression with nbd: sysfs: cannot create duplicate filename '/dev/block/43:0' Revert it before 5.18-rc1 and we'll investigage this separately in due time.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025022607-CVE-2022-49140-974f@gregkh/T
This CVE has been rejected upstream: https://lore.kernel.org/linux-cve-announce/2025022622-REJECTED-06e7@gregkh/