Fallos del tipo CWE-416

5138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar uma área de memória que já foi liberada (deallocated). O programa continua usando um ponteiro que aponta para um endereço inválido, causando leitura/escrita em memória não controlada. Isso pode levar a crash, corrupção de dados ou execução arbitrária de código.

Ejemplo

Um navegador aloca memória para um objeto DOM, depois o remove da página e libera a memória. Se um script JavaScript ainda tentar acessar esse objeto deletado, o navegador tenta ler/escrever em um endereço que agora contém outro dado, causando comportamento impredizível ou exploração por atacante.

Cómo mitigar

Use linguagens com garbage collection (Java, Python, C#) ou práticas rigorosas: null os ponteiros após free(), use smart pointers (C++), evite compartilhamento de referências sem sincronização, faça testes de memória com ferramentas como Valgrind ou AddressSanitizer.

CVE-2024-56605HIGHBluetooth: L2CAP: do not leave dangling sk pointer on error in l2cap_sock_create()EPSS 0.2%CVE-2023-52999HIGHnet: fix UaF in netns ops registration error pathEPSS 0.2%CVE-2026-53264HIGHnet/sched: act_api: use RCU with deferred freeing for action lifecycleEPSS 0.2%CVE-2023-4244HIGHUse-after-free in Linux kernel's netfilter: nf_tables componentEPSS 0.2%CVE-2025-9386MEDIUMappneta tcpreplay tcprewrite get.c get_l2len_protocol use after freeEPSS 0.2%CVE-2022-3424HIGHA use-after-free flaw was found in the Linux kernel’s SGI GRU driver in the way the first gru_file_unlocked_ioctl function is called by the EPSS 0.2%CVE-2024-26598HIGHKVM: arm64: vgic-its: Avoid potential UAF in LPI translation cacheEPSS 0.2%CVE-2024-58013HIGHBluetooth: MGMT: Fix slab-use-after-free Read in mgmt_remove_adv_monitor_syncEPSS 0.2%CVE-2026-100761HIGHPrivilege escalation due to use-after-free in the Graphics: WebGPU componentEPSS 0.2%CVE-2024-53170HIGHblock: fix uaf for flush rq while iterating tagsEPSS 0.2%CVE-2026-76875MEDIUMPyPy pyexpat ExternalEntityParserCreate Use-After-FreeEPSS 0.2%CVE-2024-42326MEDIUMUse after free vulnerability in browser.cEPSS 0.2%CVE-2024-56551HIGHdrm/amdgpu: fix usage slab after freeEPSS 0.2%CVE-2024-53208HIGHBluetooth: MGMT: Fix slab-use-after-free Read in set_powered_syncEPSS 0.2%CVE-2026-11250CRITICALInappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer EPSS 0.2%CVE-2024-50226HIGHcxl/port: Fix use-after-free, permit out-of-order decoder shutdownEPSS 0.2%CVE-2023-52926HIGHio_uring/rw: split io_read() into a helperEPSS 0.2%CVE-2024-53103HIGHhv_sock: Initializing vsk->trans to NULL to prevent a dangling pointerEPSS 0.2%CVE-2024-56658HIGHnet: defer final 'struct net' free in netns dismantleEPSS 0.2%CVE-2023-46691HIGHUse after free in Intel(R) Power Gadget software for Windows all versions may allow an authenticated user to potentially enable escalation oEPSS 0.2%