Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2023-3863MEDIUMUse-after-free in nfc_llcp_find_loca in net/nfc/llcp_core.cEPSS 0.2%CVE-2025-21999HIGHproc: fix UAF in proc_get_inode()EPSS 0.2%CVE-2025-8837MEDIUMJasPer JPEG2000 File jpc_dec.c jpc_dec_dump use after freeEPSS 0.2%CVE-2026-14398CRITICALUse after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafEPSS 0.2%CVE-2023-52800MEDIUMwifi: ath11k: fix htt pktlog lockingEPSS 0.2%CVE-2025-21722HIGHnilfs2: do not force clear folio if buffer is referencedEPSS 0.2%CVE-2026-14419CRITICALUse after free in Skia in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a craftEPSS 0.2%CVE-2022-48754HIGHphylib: fix potential use-after-freeEPSS 0.2%CVE-2023-1990MEDIUMA use-after-free flaw was found in ndlc_remove in drivers/nfc/st-nci/ndlc.c in the Linux Kernel. This flaw could allow an attacker to crash EPSS 0.2%CVE-2024-57959MEDIUMUse-After-Free (UAF) vulnerability in the display module Impact: Successful exploitation of this vulnerability may cause features to performEPSS 0.2%CVE-2026-17811HIGHUse after free in ANGLE in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to potentially perform a sandbox escapeEPSS 0.2%CVE-2026-12455HIGHUse after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UIEPSS 0.2%CVE-2026-12015MEDIUMUse after free in Autofill in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to obEPSS 0.2%CVE-2026-54522LOWMessagePack::Buffer#clear Use-After-Free that Enables Cross-Buffer DisclosureEPSS 0.2%CVE-2026-84783HIGHUse-After-Free in X.509 Extension Cache Under Concurrent UseEPSS 0.2%CVE-2022-49127HIGHref_tracker: implement use-after-free detectionEPSS 0.2%CVE-2026-14425CRITICALUse after free in ANGLE in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to potentially perform a sandbox escape via a crafEPSS 0.2%CVE-2025-8842MEDIUMNASM Netwide Assember preproc.c do_directive use after freeEPSS 0.2%CVE-2025-21969HIGHBluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmdEPSS 0.2%CVE-2023-52446HIGHbpf: Fix a race condition between btf_put() and map_free()EPSS 0.2%