
Cloud Vulnerability DB
A community-led vulnerabilities database
A vulnerability in the Linux kernel has been identified and assigned CVE-2025-40203. The issue relates to the listmount functionality where path_put() is called under namespace semaphore, which could lead to potential system instability. The vulnerability was disclosed on November 12, 2025 (NVD).
The vulnerability specifically involves the listmount() function in the Linux kernel, where calling path_put() under the namespace semaphore could result in system issues if the last reference is released. The issue requires massage of the listmount() function to ensure proper handling of path references under namespace operations (Kernel.org).
If exploited, this vulnerability could potentially lead to system instability when the last reference is released during listmount operations (Ubuntu).
The vulnerability has been resolved in the Linux kernel through patches that modify the listmount() function to prevent calling path_put() under the namespace semaphore (NVD).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."