CVE-2025-40203 — Improper Control of a Resource Through its Lifetime in Linux
Severity
5.8MEDIUM
No vectorEPSS
0.0%
top 94.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 12
Latest updateFeb 24
Description
In the Linux kernel, the following vulnerability has been resolved:
listmount: don't call path_put() under namespace semaphore
Massage listmount() and make sure we don't call path_put() under the
namespace semaphore. If we put the last reference we're fscked.
Affected Packages5 packages
▶CVEListV5linux/linuxb4c2bea8ceaa50cd42a8f73667389d801a3ecf2d — 659874b7ee4976ad9ce476e07fd36bc67b3537f1+3