CVE-2025-40062
Published Oct 28, 2025
Modified Apr 15, 2026
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs When the initialization of qm->debug.acc_diff_reg fails, the probe process does not exit. However, after qm->debug.qm_diff_regs is freed, it is not set to NULL. This can lead to a double free when the remove process attempts to free it again. Therefore, qm->debug.qm_diff_regs should be set to NULL after it is freed.
Is your site exposed to CVE-2025-40062?
Run a free security scan — no signup, results in seconds.
References
Other References
https://git.kernel.org/stable/c/1750f1ec143ebabdbdfa013668665c9d5042c430
https://git.kernel.org/stable/c/7226a0650ad5705bd8d39a11be270fa21ed1e6a5
https://git.kernel.org/stable/c/a7836260d5121949ba734e840d42a86ab4a32fcc
https://git.kernel.org/stable/c/a87a21a56244b8f4eb357f6bad879247005bbe38
https://git.kernel.org/stable/c/f0cafb02de883b3b413d34eb079c9680782a9cc1
Frequently Asked Questions
What is CVE-2025-40062? +
In the Linux kernel, the following vulnerability has been resolved:
crypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs
When the initialization of qm->debug.acc_diff_reg fails,
the probe process does not exit. However, after qm->debug.qm_diff_regs is
freed, it is not set to NULL. This can lead to a double free when the
remove process attempts to free it again. Therefore, qm->debug.qm_diff_regs
should be set to NULL after it is freed.
How do I check if I'm vulnerable to CVE-2025-40062? +
You can use Secably's free Website Scanner to check your website for known vulnerabilities. For infrastructure scanning, use the Port Scanner to identify exposed services that may be affected. Check the vendor advisories linked above for specific patch and version information.