CVE-2025-40062
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
28/10/2025
Last modified:
30/10/2025
Description
In the Linux kernel, the following vulnerability has been resolved:<br />
<br />
crypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs<br />
<br />
When the initialization of qm->debug.acc_diff_reg fails,<br />
the probe process does not exit. However, after qm->debug.qm_diff_regs is<br />
freed, it is not set to NULL. This can lead to a double free when the<br />
remove process attempts to free it again. Therefore, qm->debug.qm_diff_regs<br />
should be set to NULL after it is freed.
Impact
References to Advisories, Solutions, and Tools
- https://git.kernel.org/stable/c/1750f1ec143ebabdbdfa013668665c9d5042c430
- https://git.kernel.org/stable/c/7226a0650ad5705bd8d39a11be270fa21ed1e6a5
- https://git.kernel.org/stable/c/a7836260d5121949ba734e840d42a86ab4a32fcc
- https://git.kernel.org/stable/c/a87a21a56244b8f4eb357f6bad879247005bbe38
- https://git.kernel.org/stable/c/f0cafb02de883b3b413d34eb079c9680782a9cc1



