Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-22097HIGHdrm/vkms: Fix use after free and double free on init errorEPSS 0.2%CVE-2024-9126HIGHUse after free in Internals in Google Chrome on iOS prior to 127.0.6533.88 allowed a remote attacker who convinced a user to engage in speciEPSS 0.2%CVE-2026-11647HIGHUse after free in Printing in Google Chrome on Android prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer prEPSS 0.2%CVE-2025-21861MEDIUMmm/migrate_device: don't add folio to be freed to LRU in migrate_device_finalize()EPSS 0.2%CVE-2026-12464HIGHUse after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potEPSS 0.2%CVE-2026-100805HIGHRace condition, use-after-free in the Audio/Video componentEPSS 0.2%CVE-2024-56623HIGHscsi: qla2xxx: Fix use after free on unloadEPSS 0.2%CVE-2023-52576MEDIUMx86/mm, kexec, ima: Use memblock_free_late() from ima_free_kexec_buffer()EPSS 0.2%CVE-2024-53068HIGHfirmware: arm_scmi: Fix slab-use-after-free in scmi_bus_notifier()EPSS 0.2%CVE-2023-40140HIGHIn android_view_InputDevice_create of android_view_InputDevice.cpp, there is a possible way to execute arbitrary code due to a use after freEPSS 0.2%CVE-2025-54229HIGHAdobe Framemaker | Use After Free (CWE-416)EPSS 0.2%CVE-2026-10003HIGHUse after free in Views in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gesEPSS 0.2%CVE-2024-50261HIGHmacsec: Fix use-after-free while sending the offloading packetEPSS 0.2%CVE-2026-3779HIGHFoxit PDF Editor/Reader List Box Calculate Array Use-After-Free VulnerabilityEPSS 0.2%CVE-2023-1252HIGHA use-after-free flaw was found in the Linux kernel’s Ext4 File System in how a user triggers several file operations simultaneously with thEPSS 0.2%CVE-2024-56759HIGHbtrfs: fix use-after-free when COWing tree bock and tracing is enabledEPSS 0.2%CVE-2024-56541HIGHwifi: ath12k: fix use-after-free in ath12k_dp_cc_cleanup()EPSS 0.2%CVE-2025-54258HIGHSubstance3D - Modeler | Use After Free (CWE-416)EPSS 0.2%CVE-2024-57892HIGHocfs2: fix slab-use-after-free due to dangling pointer dqi_privEPSS 0.2%CVE-2024-41149HIGHblock: avoid to reuse `hctx` not removed from cpuhp callback listEPSS 0.2%