Weaknesses of type CWE-416

5,149 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2025-39861HIGHBluetooth: vhci: Prevent use-after-free by removing debugfs files earlyEPSS 0.2%CVE-2026-58090HIGHUse-after-free in unix SOCK_STREAM message handlingEPSS 0.2%CVE-2026-58091HIGHKernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctlEPSS 0.2%CVE-2023-5091HIGHMali GPU Kernel Driver allows improper GPU processing operationsEPSS 0.2%CVE-2026-49412HIGHUse-after-free bug in the IPV6_MSFILTER socket option handlerEPSS 0.2%CVE-2026-43808MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOEPSS 0.2%CVE-2024-22180LOWCamera has a use after free vulnerabilityEPSS 0.2%CVE-2024-56556HIGHbinder: fix node UAF in binder_add_freeze_work()EPSS 0.2%CVE-2026-0465MEDIUMA Use‑After‑Free (UAF) vulnerability in the AMD Ryzen™ Master Utility Driver could allow a local attacker to access kernel memory, potentialEPSS 0.2%CVE-2025-20081LOWCommunication Dsoftbus has an UAF vulnerabilityEPSS 0.2%CVE-2023-49142MEDIUMmultimedia audio has a UAF vulnerabilityEPSS 0.2%CVE-2025-13350HIGHUse-after-free of orphaned AF_UNIX in Ubuntu builds of Linux kernelEPSS 0.2%CVE-2026-87633HIGHUse after free in Views in Google Chrome prior to 153.0.8010.36 allowed a local attacker to execute arbitrary code outside the sandbox via UEPSS 0.2%CVE-2025-39882HIGHdrm/mediatek: fix potential OF node use-after-freeEPSS 0.2%CVE-2025-0073HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2023-5249HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2025-39854HIGHice: fix NULL access of tx->in_use in ice_ll_ts_intrEPSS 0.2%CVE-2023-53426HIGHxsk: Fix xsk_diag use-after-free error during socket cleanupEPSS 0.2%CVE-2026-13282MEDIUMUse after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruptiEPSS 0.2%CVE-2024-23373HIGHUse After Free in GraphicsEPSS 0.1%