Weaknesses of type CWE-416

5,183 results

Uso após liberação de memória

Ocorre quando o código tenta acessar um bloco de memória que já foi desalocado (free/delete). O ponteiro continua apontando para aquele endereço, mas o dado ali pode ter sido sobrescrito por outra operação, causando comportamento impredizível, corrupção de dados ou execução de código arbitrário.

Example

Um buffer é alocado, depois liberado com free(). Mais adiante, o código ainda tenta ler ou escrever naquele mesmo ponteiro sem verificar. Se um atacante controlar a alocação subsequente daquele endereço, consegue manipular o conteúdo que será lido.

How to mitigate

Anule o ponteiro imediatamente após liberar (ptr = NULL), implemente análise estática para detectar acessos pós-liberação, use ferramentas como valgrind ou AddressSanitizer nos testes, e considere linguagens com gerenciamento automático de memória para código sensível.

CVE-2023-35685HIGHIn DevmemIntMapPages of devicemem_server.c, there is a possible physical page uaf due to a logic error in the code. This could lead to localEPSS 0.1%CVE-2026-0027MEDIUMIn smmu_detach_dev of arm-smmu-v3.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation ofEPSS 0.1%CVE-2026-26203MEDIUMPJSIP's pjmedia-video has use-after-free in H264 packetizer when packetizing fragmented NALEPSS 0.1%CVE-2023-53252HIGHBluetooth: use RCU for hci_conn_params and iterate safely in hci_syncEPSS 0.1%CVE-2024-23373HIGHUse After Free in GraphicsEPSS 0.1%CVE-2026-10667HIGHSMP use-after-free in Zephyr `CONFIG_USERSPACE` dynamic kernel-object tracking, reachable from unprivileged user threadsEPSS 0.1%CVE-2023-53386HIGHBluetooth: Fix potential use-after-free when clear keysEPSS 0.1%CVE-2023-53427HIGHcifs: Fix warning and UAF when destroy the MR listEPSS 0.1%CVE-2023-53446HIGHPCI/ASPM: Disable ASPM on MFD function removal to avoid use-after-freeEPSS 0.1%CVE-2026-55510MEDIUMImageMagick: Use-After-Free in crafted 8BIM when identifying an imageEPSS 0.1%CVE-2023-53377HIGHcifs: prevent use-after-free by freeing the cfile laterEPSS 0.1%CVE-2022-1974—A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject creation and delete. ThEPSS 0.1%CVE-2025-27128HIGHliteos_a has an UAF vulnerabilityEPSS 0.1%CVE-2025-24298HIGHliteos_a has an UAF vulnerabilityEPSS 0.1%CVE-2026-5942MEDIUMFoxit PDF Editor/Reader AcroForm Signature Use-After-Free VulnerabilityEPSS 0.1%CVE-2025-9157MEDIUMappneta tcpreplay tcprewrite edit_packet.c untrunc_packet use after freeEPSS 0.1%CVE-2025-39896HIGHaccel/ivpu: Prevent recovery work from being queued during device removalEPSS 0.1%CVE-2026-13037HIGHUse after free in WebView in Google Chrome on Android prior to 149.0.7827.197 allowed a local attacker to execute arbitrary code inside a saEPSS 0.1%CVE-2023-53398HIGHmlx5: fix possible ptp queue fifo use-after-freeEPSS 0.1%CVE-2025-13120MEDIUMmruby array.c sort_cmp use after freeEPSS 0.1%