CVE-2025-40062
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs When the initialization of qm->debug.acc_diff_reg fails, the probe process does not exit.
Does this matter?
Not yet scored. NVD analysis is pending; check back once CVSS and EPSS values are published.
Description
In the Linux kernel, the following vulnerability has been resolved: crypto: hisilicon/qm - set NULL to qm->debug.qm_diff_regs When the initialization of qm->debug.acc_diff_reg fails, the probe process does not exit. However, after qm->debug.qm_diff_regs is freed, it is not set to NULL. This can lead to a double free when the remove process attempts to free it again. Therefore, qm->debug.qm_diff_regs should be set to NULL after it is freed.
- CVSS
- Not yet scored
- EPSS
- 0.19% probability · 8th percentile
- CISA KEV
- Not listed
- Source
- 416baaa9-dc9f-4396-8d5f-8c081fb06d67
References
- https://git.kernel.org/stable/c/1750f1ec143ebabdbdfa013668665c9d5042c430
- https://git.kernel.org/stable/c/7226a0650ad5705bd8d39a11be270fa21ed1e6a5
- https://git.kernel.org/stable/c/a7836260d5121949ba734e840d42a86ab4a32fcc
- https://git.kernel.org/stable/c/a87a21a56244b8f4eb357f6bad879247005bbe38
- https://git.kernel.org/stable/c/f0cafb02de883b3b413d34eb079c9680782a9cc1
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.