kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace.
https://www.openwall.com/lists/oss-security/2022/01/29/1
https://security.netapp.com/advisory/ntap-20220221-0001/
https://github.com/torvalds/linux/commit/f9d87929d451d3e649699d0f1d74f71f77ad38f5