Falhas do tipo CWE-416

5.134 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2021-42706HIGHAzeoTech DAQFactoryEPSS 0.3%CVE-2022-49388HIGHubi: ubi_create_volume: Fix use-after-free when volume creation failedEPSS 0.3%CVE-2026-55318HIGHIn multiple locations, there is a possible use-after-free due to a race condition. This could lead to remote code execution with no additionEPSS 0.3%CVE-2022-49695HIGHigb: fix a use-after-free issue in igb_clean_tx_ringEPSS 0.3%CVE-2025-54223HIGHInCopy | Use After Free (CWE-416)EPSS 0.3%CVE-2024-46740HIGHbinder: fix UAF caused by offsets overwriteEPSS 0.3%CVE-2022-49667HIGHnet: bonding: fix use-after-free after 802.3ad slave unbindEPSS 0.3%CVE-2025-54108HIGHCapability Access Management Service (camsvc) Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-49411HIGHbfq: Make sure bfqg for which we are queueing requests is onlineEPSS 0.3%CVE-2022-49647HIGHcgroup: Use separate src/dst nodes when preloading css_sets for migrationEPSS 0.3%CVE-2022-49413HIGHbfq: Update cgroup information before merging bioEPSS 0.3%CVE-2025-53807HIGHWindows Graphics Component Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-1973—A use-after-free flaw was found in the Linux kernel in log_replay in fs/ntfs3/fslog.c in the NTFS journal. This flaw allows a local attackerEPSS 0.3%CVE-2024-53239HIGHALSA: 6fire: Release resources at card releaseEPSS 0.3%CVE-2022-1184—A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the Linux kernel’s filesystem sub-component. This flaw allows a locaEPSS 0.3%CVE-2024-56631HIGHscsi: sg: Fix slab-use-after-free read in sg_release()EPSS 0.3%CVE-2023-31974MEDIUMyasm v1.3.0 was discovered to contain a use after free via the function error at /nasm/nasm-pp.c. Note: Multiple third parties dispute this EPSS 0.3%CVE-2025-59210HIGHWindows Resilient File System (ReFS) Deduplication Service Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-49426HIGHiommu/arm-smmu-v3-sva: Fix mm use-after-freeEPSS 0.3%CVE-2022-49696HIGHtipc: fix use-after-free Read in tipc_named_reinitEPSS 0.3%