Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-21631HIGHblock, bfq: fix waker_bfqq UAF after bfq_split_bfqq()EPSS 0.2%CVE-2026-64718MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.6, Safari 27, iOS 26.6 and iPadOS 26.EPSS 0.2%CVE-2024-14028MEDIUMMultiple implicit reads in parallel can result in a crash or denial of serviceEPSS 0.2%CVE-2026-21287HIGHSubstance3D - Stager | Use After Free (CWE-416)EPSS 0.2%CVE-2025-21652HIGHipvlan: Fix use-after-free in ipvlan_get_iflink().EPSS 0.2%CVE-2023-3397HIGHKernel: slab-use-after-free write in txend due to race conditionEPSS 0.2%CVE-2024-8422HIGHCWE-416: Use After Free vulnerability exists that could cause arbitrary code execution, denial of service and loss of confidentiality & inteEPSS 0.2%CVE-2024-57887HIGHdrm: adv7511: Fix use-after-free in adv7533_attach_dsi()EPSS 0.2%CVE-2023-53322HIGHscsi: qla2xxx: Wait for io return on terminate rportEPSS 0.2%CVE-2024-32929HIGHIn gpu_slc_get_region of pixel_gpu_slc.c, there is a possible EoP due to a use after free. This could lead to local escalation of privilege EPSS 0.2%CVE-2024-50084HIGHnet: microchip: vcap api: Fix memory leaks in vcap_api_encode_rule_test()EPSS 0.2%CVE-2024-56765HIGHpowerpc/pseries/vas: Add close() callback in vas_vm_ops structEPSS 0.2%CVE-2025-6555MEDIUMUse after free in Animation in Google Chrome prior to 138.0.7204.49 allowed a remote attacker to potentially exploit heap corruption via a cEPSS 0.2%CVE-2025-46710MEDIUMPossible kernel exceptions caused by reading and writing kernel heap data after free.EPSS 0.2%CVE-2023-1195MEDIUMA use-after-free flaw was found in reconn_set_ipaddr_from_hostname in fs/cifs/connect.c in the Linux kernel. The issue occurs when it forgetEPSS 0.2%CVE-2025-54335MEDIUMAn issue was discovered in the GPU driver in Samsung Mobile Processor Exynos 1480, 2400, 1580, 2500. There is a use-after-free in the XclipsEPSS 0.2%CVE-2026-11154HIGHUse after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentiEPSS 0.2%CVE-2021-22545HIGHUse-after-free in BinDiffEPSS 0.2%CVE-2026-102760HIGHWhen NetX Secure is built with `NX_SECURE_KEY_CLEAR`, every TLS record sent on an active session is wiped after it has been handed to TCP. BEPSS 0.2%CVE-2025-22068HIGHublk: make sure ubq->canceling is set when queue is frozenEPSS 0.2%