Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-84783HIGHUse-After-Free in X.509 Extension Cache Under Concurrent UseEPSS 0.2%CVE-2022-49127HIGHref_tracker: implement use-after-free detectionEPSS 0.2%CVE-2023-53305HIGHBluetooth: L2CAP: Fix use-after-freeEPSS 0.2%CVE-2024-0775MEDIUMKernel: use-after-free while changing the mount option in __ext4_remount leadingEPSS 0.2%CVE-2026-9904HIGHUse after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a craEPSS 0.2%CVE-2026-9899HIGHUse after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potenEPSS 0.2%CVE-2026-12012HIGHUse after free in Network in Google Chrome prior to 149.0.7827.115 allowed an attacker in a privileged network position to potentially exploEPSS 0.2%CVE-2024-49570HIGHdrm/xe/tracing: Fix a potential TP_printk UAFEPSS 0.2%CVE-2026-11306HIGHUse after free in PDFium in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a EPSS 0.2%CVE-2022-28192MEDIUMNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager (nvidia.ko), where it may lead to a use-after-free, which in turn mEPSS 0.2%CVE-2024-53182HIGHRevert "block, bfq: merge bfq_release_process_ref() into bfq_put_cooperator()"EPSS 0.2%CVE-2023-52566MEDIUMnilfs2: fix potential use after free in nilfs_gccache_submit_read_data()EPSS 0.2%CVE-2026-12020HIGHUse after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption EPSS 0.2%CVE-2021-47670HIGHcan: peak_usb: fix use after free bugsEPSS 0.2%CVE-2024-58083HIGHKVM: Explicitly verify target vCPU is online in kvm_get_vcpu()EPSS 0.2%CVE-2024-56604HIGHBluetooth: RFCOMM: avoid leaving dangling sk pointer in rfcomm_sock_alloc()EPSS 0.2%CVE-2026-11670HIGHUse after free in PDF in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code inside a sandbox via a crEPSS 0.2%CVE-2024-56678HIGHpowerpc/mm/fault: Fix kfence page fault reportingEPSS 0.2%CVE-2025-54230HIGHAdobe Framemaker | Use After Free (CWE-416)EPSS 0.2%CVE-2026-6362MEDIUMUse after free in Codecs in Google Chrome prior to 147.0.7727.101 allowed a remote attacker to potentially perform out of bounds memory acceEPSS 0.2%