CVE-2025-40062
Linux Kernel vulnerability analysis and mitigation

Overview

CVE-2025-40062 is a vulnerability discovered in the Linux kernel, specifically affecting the crypto: hisilicon/qm component. The vulnerability was published on October 28, 2025, and involves a potential double-free condition in the memory management of qm->debug.qmdiffregs (NVD).

Technical details

The vulnerability occurs when the initialization of qm->debug.accdiffreg fails, but the probe process continues execution. The issue arises because after qm->debug.qmdiffregs is freed, it is not set to NULL. This oversight can lead to a double-free vulnerability when the remove process attempts to free the same memory location again (NVD).

Impact

The vulnerability affects multiple Linux distributions including Ubuntu's newer releases (25.10 questing, 25.04 plucky, and 24.04 LTS noble) and Debian's bookworm release. Various kernel versions across different platforms including AWS, Azure, and GCP configurations are impacted (Ubuntu).

Mitigation and workarounds

The vulnerability has been addressed in Debian's security update (version 6.1.158-1). For Ubuntu systems, updates are being worked on for affected versions. Older releases such as Ubuntu 22.04 LTS jammy, 20.04 LTS focal, and 18.04 LTS bionic are not affected by this vulnerability (Ubuntu).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40258HIGH7
  • Linux KernelLinux Kernel
  • kernel-zfcpdump-devel-matched
NoNoDec 04, 2025
CVE-2025-40259MEDIUM6.2
  • Linux KernelLinux Kernel
  • kernel-64k-devel
NoNoDec 04, 2025
CVE-2025-40264MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-rt-64k-debug-kvm
NoNoDec 04, 2025
CVE-2025-40254MEDIUM5.5
  • Linux KernelLinux Kernel
  • kernel-modules-partner
NoNoDec 04, 2025
CVE-2025-40253MEDIUM5.5
  • Linux KernelLinux Kernel
  • python3-perf
NoNoDec 04, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management