In the Linux kernel, the following vulnerability has been resolved:
fs: don't try and remove empty rbtree node
When copying a namespace we won't have added the new copy into the namespace rbtree until after the copy succeeded. Calling freemntns() will try to remove the copy from the rbtree which is invalid. Simply free the namespace skeleton directly.