cbcvebase.
CVE-2025-40062
published 2025-10-28

CVE-2025-40062: In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs When the initialization of…

PriorityP421high7.8
EPSS
0.19%
8.5th percentile
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs When the initialization of qm->debug.acc_diff_reg fails, the probe process does not exit. However, after qm->debug.qm_diff_regs is freed, it is not set to NULL. This can lead to a double free when the remove process attempts to free it again. Therefore, qm->debug.qm_diff_regs should be set to NULL after it is freed.

Affected

24 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
debianlinux-6.1< linux 6.1.158-1 (bookworm)linux 6.1.158-1 (bookworm)
linuxlinux
linuxlinux
linuxlinux>= 6.1.98 < 6.1.1566.1.156
linuxlinux>= 6.6.39 < 6.6.1126.6.112
linuxlinux>= 6.9.9 < 6.106.10
linuxlinux>= 7fc8d9a525b5c3f8dfa5ed50901e764d8ede7e1e < 1750f1ec143ebabdbdfa013668665c9d5042c4301750f1ec143ebabdbdfa013668665c9d5042c430
linuxlinux>= 8be0913389718e8d27c4f1d4537b5e1b99ed7739 < a87a21a56244b8f4eb357f6bad879247005bbe38a87a21a56244b8f4eb357f6bad879247005bbe38
linuxlinux>= 8be0913389718e8d27c4f1d4537b5e1b99ed7739 < 7226a0650ad5705bd8d39a11be270fa21ed1e6a57226a0650ad5705bd8d39a11be270fa21ed1e6a5
linuxlinux>= 8be0913389718e8d27c4f1d4537b5e1b99ed7739 < f0cafb02de883b3b413d34eb079c9680782a9cc1f0cafb02de883b3b413d34eb079c9680782a9cc1
linuxlinux>= eda60520cfe3aba9f088c68ebd5bcbca9fc6ac3c < a7836260d5121949ba734e840d42a86ab4a32fcca7836260d5121949ba734e840d42a86ab4a32fcc
linuxlinux_kernel>= 0 < 6.1.158-16.1.158-1
linuxlinux_kernel>= 0 < 6.12.57-16.12.57-1
linuxlinux_kernel>= 0 < 6.17.6-16.17.6-1
linuxlinux_kernel>= 0 < 6.1.1566.1.156
linuxlinux_kernel>= 0 < 6.8.0-106.1066.8.0-106.106
linuxlinux_kernel>= 0 < 6.17.0-14.146.17.0-14.14
linuxlinux_kernel>= 6.10.0 < 6.17.36.17.3
linuxlinux_kernel>= 6.2.0 < 6.6.1126.6.112
linuxlinux_kernel>= 6.7.0 < 6.12.536.12.53
ubuntulinux-aws
ubuntulinux-oracle
ubuntulinux-xilinx

CVSS provenance

vendor_ubuntu7.8HIGH
osv3.2LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.