Weaknesses of type CWE-416

5,143 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2025-21999HIGHproc: fix UAF in proc_get_inode()EPSS 0.2%CVE-2026-8521HIGHUse after free in Tab Groups in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code via malicious netwEPSS 0.2%CVE-2023-1990MEDIUMA use-after-free flaw was found in ndlc_remove in drivers/nfc/st-nci/ndlc.c in the Linux Kernel. This flaw could allow an attacker to crash EPSS 0.2%CVE-2026-12455HIGHUse after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UIEPSS 0.2%CVE-2026-14419CRITICALUse after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a craftEPSS 0.2%CVE-2026-12015MEDIUMUse after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obEPSS 0.2%CVE-2022-48754HIGHphylib: fix potential use-after-freeEPSS 0.2%CVE-2023-33200MEDIUMMali GPU Kernel Driver Allows Improper GPU Memory Processing OperationsEPSS 0.2%CVE-2026-14398CRITICALUse after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafEPSS 0.2%CVE-2023-34970MEDIUMMali GPU Kernel Driver Allows Improper GPU Memory Processing OperationsEPSS 0.2%CVE-2023-52800MEDIUMwifi: ath11k: fix htt pktlog lockingEPSS 0.2%CVE-2026-54522LOWMessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer DisclosureEPSS 0.2%CVE-2025-21722HIGHnilfs2: do not force clear folio if buffer is referencedEPSS 0.2%CVE-2026-17811HIGHUse after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escapeEPSS 0.2%CVE-2024-57959MEDIUMUse-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause features to performEPSS 0.2%CVE-2025-8842MEDIUMNASM Netwide Assember preproc.c do_directive use after freeEPSS 0.2%CVE-2024-50114HIGHKVM: arm64: Unregister redistributor for failed vCPU creationEPSS 0.2%CVE-2025-21751HIGHnet/mlx5: HWS, change error flow on matcher disconnectEPSS 0.2%CVE-2023-52446HIGHbpf: Fix a race condition between btf_put() and map_free()EPSS 0.2%CVE-2025-21969HIGHBluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmdEPSS 0.2%