
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40062 is a vulnerability discovered in the Linux kernel, specifically affecting the crypto: hisilicon/qm component. The vulnerability was published on October 28, 2025, and involves a potential double-free condition in the memory management of qm->debug.qmdiffregs (NVD).
The vulnerability occurs when the initialization of qm->debug.accdiffreg fails, but the probe process continues execution. The issue arises because after qm->debug.qmdiffregs is freed, it is not set to NULL. This oversight can lead to a double-free vulnerability when the remove process attempts to free the same memory location again (NVD).
The vulnerability affects multiple Linux distributions including Ubuntu's newer releases (25.10 questing, 25.04 plucky, and 24.04 LTS noble) and Debian's bookworm release. Various kernel versions across different platforms including AWS, Azure, and GCP configurations are impacted (Ubuntu).
The vulnerability has been addressed in Debian's security update (version 6.1.158-1). For Ubuntu systems, updates are being worked on for affected versions. Older releases such as Ubuntu 22.04 LTS jammy, 20.04 LTS focal, and 18.04 LTS bionic are not affected by this vulnerability (Ubuntu).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."