Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2024-7675HIGHDWFX File Parsing Vulnerabilities in Autodesk Navisworks Desktop SoftwareEPSS 0.2%CVE-2025-68656MEDIUMEspressif ESP-IDF USB Host HID (Human Interface Device) Driver Descriptor Use-After-Free VulnerabilityEPSS 0.2%CVE-2025-8410MEDIUMUse After Free vulnerability in RTI Connext Professional (Security Plugins) allows File Manipulation.EPSS 0.2%CVE-2025-68617HIGHUse after free in fluidsynthEPSS 0.2%CVE-2024-57896HIGHbtrfs: flush delalloc workers queue before stopping cleaner kthread during unmountEPSS 0.2%CVE-2026-41982MEDIUMRace condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.2%CVE-2024-56669HIGHiommu/vt-d: Remove cache tags before disabling ATSEPSS 0.2%CVE-2025-20062HIGHUse after free for some Intel(R) PROSet/Wireless WiFi Software for Windows before version 23.100 may allow an unauthenticated user to potentEPSS 0.2%CVE-2024-57857HIGHRDMA/siw: Remove direct link to net_deviceEPSS 0.2%CVE-2024-56652HIGHdrm/xe/reg_sr: Remove register poolEPSS 0.2%CVE-2023-28984MEDIUMJunos OS: QFX Series: The PFE may crash when a lot of MAC addresses are being learned and agedEPSS 0.2%CVE-2024-46973HIGHExploitable kernel use-after-free on psServerMMUContext due to reference count mismanagementEPSS 0.2%CVE-2024-50293HIGHnet/smc: do not leave a dangling sk pointer in __smc_create()EPSS 0.2%CVE-2024-1065MEDIUMMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2026-70582MEDIUMWindows Management Instrumentation Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2025-9394MEDIUMPoDoFo PDF Dictionary PdfTokenizer.cpp DetermineDataType use after freeEPSS 0.2%CVE-2023-53374HIGHBluetooth: hci_conn: fail SCO/ISO via hci_conn_failed if ACL gone earlyEPSS 0.2%CVE-2024-53143HIGHfsnotify: Fix ordering of iput() and watched_objects decrementEPSS 0.2%CVE-2026-33021HIGHlibsixel: Use-after-free in sixel_encoder_encode_bytes()EPSS 0.2%CVE-2025-21631HIGHblock, bfq: fix waker_bfqq UAF after bfq_split_bfqq()EPSS 0.2%