In the Linux kernel, the following vulnerability has been resolved: listmount: don't call path_put() under namespace semaphore Massage listmount() and make sure we don't call path_put() under the namespace semaphore. If we put the last reference we're fscked.
Upstream advisory: https://lore.kernel.org/linux-cve-announce/2025111247-CVE-2025-40203-c83b@gregkh/T