In the Linux kernel, the following vulnerability has been resolved:
spufs: fix a leak on spufsnewfile() failure
It's called from spufsfilldir(), and caller of that will do spufs_rmdir() in case of failure. That does remove everything we'd managed to create, but... the problem dentry is still negative. IOW, it needs to be explicitly dropped.