In the Linux kernel, the following vulnerability has been resolved: spufs: fix a leak on spufs_new_file() failure It's called from spufs_fill_dir(), and caller of that will do spufs_rmdir() in case of failure. That does remove everything we'd managed to create, but... the problem dentry is still negative. IOW, it needs to be explicitly dropped.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025041611-CVE-2025-22073-4f4b@gregkh/T