Falhas do tipo CWE-416

5.134 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-24869HIGHUse-after-free in the Layout: Scrolling and Overflow componentEPSS 0.3%CVE-2026-25171HIGHWindows Authentication Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2026-25170HIGHWindows Hyper-V Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-2327HIGHUse-after-free in io_uring ad work_flags in Linux KernelEPSS 0.3%CVE-2026-25178HIGHWindows Ancillary Function Driver for WinSock Elevation of Privilege VulnerabilityEPSS 0.3%CVE-2022-32914HIGHA use after free issue was addressed with improved memory management. This issue is fixed in macOS Big Sur 11.7, macOS Ventura 13, iOS 16, wEPSS 0.3%CVE-2026-11643HIGHUse after free in Proxy in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via malicious network tEPSS 0.3%CVE-2023-0240HIGHUse after free in io_uring in the Linux KernelEPSS 0.3%CVE-2024-56672HIGHblk-cgroup: Fix UAF in blkcg_unpin_online()EPSS 0.3%CVE-2025-61814HIGHInDesign Desktop | Use After Free (CWE-416)EPSS 0.3%CVE-2025-61815HIGHInDesign Desktop | Use After Free (CWE-416)EPSS 0.3%CVE-2025-1290HIGHA race condition Use-After-Free vulnerability exists in the virtio_transport_space_update function within the Kernel 5.4 on ChromeOS. ConcurEPSS 0.3%CVE-2026-12462HIGHUse after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to execuEPSS 0.3%CVE-2022-49359HIGHdrm/panfrost: Job should reference MMU not file_privEPSS 0.3%CVE-2021-33641HIGHWhen processing files, malloc stores the data of the current line. When processing comments, malloc incorrectly accesses the released memoryEPSS 0.3%CVE-2023-32269MEDIUMAn issue was discovered in the Linux kernel before 6.1.11. In net/netrom/af_netrom.c, there is a use-after-free because accept is also allowEPSS 0.3%CVE-2022-49390HIGHmacsec: fix UAF bug for real_devEPSS 0.3%CVE-2023-23586MEDIUMUse after free in io_uring in the Linux KernelEPSS 0.3%CVE-2024-56538HIGHdrm: zynqmp_kms: Unplug DRM device before removalEPSS 0.3%CVE-2024-50269HIGHusb: musb: sunxi: Fix accessing an released usb phyEPSS 0.3%