PT-2025-44130 · Hisilicon+4 · Hisilicon Qm+4

Published

2025-08-25

·

Updated

2026-05-22

·

CVE-2025-40062

CVSS v2.0

6.0

Medium

VectorAV:L/AC:H/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel (affected versions not specified)
Description A flaw exists in the Linux kernel’s crypto subsystem, specifically within the hisilicon/qm module. The issue involves a potential double free when the qm->debug.qm diff regs memory region is not set to NULL after being freed during the initialization process. This occurs when the initialization of qm->debug.acc diff reg fails, preventing the probe process from exiting and leading to a double free during the remove process.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-13609
CVE-2025-40062
DLA-4379-1
DSA-6053-1
ECHO-68FB-9945-05AC
MGASA-2025-0309
MGASA-2025-0310
OESA-2026-2417
OESA-2026-2418
OPENSUSE-SU-2025:15702-1
OPENSUSE-SU-2025:20091-1
OPENSUSE-SU-2026:10301-1
SUSE-SU-2025:21040-1
SUSE-SU-2025:21052-1
SUSE-SU-2025:21056-1
SUSE-SU-2025:21064-1
SUSE-SU-2025:21080-1
SUSE-SU-2025:21147-1
SUSE-SU-2025:21180-1
SUSE-SU-2025:4057-1
SUSE-SU-2025:4128-1
SUSE-SU-2025:4132-1
SUSE-SU-2025:4140-1
SUSE-SU-2025:4141-1
SUSE-SU-2025:4301-1
USN-8029-1
USN-8029-2
USN-8029-3
USN-8030-1
USN-8048-1
USN-8095-1
USN-8095-2
USN-8095-3
USN-8095-4
USN-8095-5
USN-8100-1
USN-8125-1
USN-8126-1
USN-8165-1
USN-8261-1

Affected Products

Linuxmint
Linux Kernel
Suse
Ubuntu
Hisilicon Qm