A recent upstream Linux kernel patch closes CVE-2025-40146, a subtle but practical concurrency bug in the block multi-queue (blk-mq) layer that could deadlock I/O when the sysfs attribute nr_requests is grown; administrators and cloud operators should treat this as an availability‑first risk and...