Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2021-22545HIGHUse-after-free in BinDiffEPSS 0.2%CVE-2026-11154HIGHUse after free in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentiEPSS 0.2%CVE-2025-33220HIGHNVIDIA vGPU software contains a vulnerability in the Virtual GPU Manager, where a malicious guest could cause heap memory access after the mEPSS 0.2%CVE-2024-9979MEDIUMPyo3: risk of use-after-free in `borrowed` reads from python weak referencesEPSS 0.2%CVE-2023-32378HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.3, macOS Big Sur 11.7.5, macOSEPSS 0.2%CVE-2026-11201HIGHUse after free in ServiceWorker in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious exteEPSS 0.2%CVE-2023-4891MEDIUM A potential use-after-free vulnerability was reported in the Lenovo View driver that could result in denial of service. EPSS 0.2%CVE-2026-40290HIGHOP-TEE has a Use-After-Free race in FF-A shared-memory teardownEPSS 0.2%CVE-2023-26589MEDIUMUse after free in some Intel(R) Aptio* V UEFI Firmware Integrator Tools may allowed an authenticated user to potentially enable denial of seEPSS 0.2%CVE-2024-58060HIGHbpf: Reject struct_ops registration that uses module ptr and the module btf_id is missingEPSS 0.2%CVE-2026-24295HIGHWindows Device Association Service Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2026-23671HIGHWindows Bluetooth RFCOM Protocol Driver Elevation of Privilege VulnerabilityEPSS 0.2%CVE-2025-22085HIGHRDMA/core: Fix use-after-free when rename device nameEPSS 0.2%CVE-2025-21923HIGHHID: hid-steam: Fix use-after-free when detaching deviceEPSS 0.2%CVE-2025-21867HIGHbpf, test_run: Fix use-after-free issue in eth_skb_pkt_type()EPSS 0.2%CVE-2025-21879HIGHbtrfs: fix use-after-free on inode when scanning root during em shrinkingEPSS 0.2%CVE-2022-50413HIGHwifi: mac80211: fix use-after-freeEPSS 0.2%CVE-2025-61662HIGHGrub2: missing unregister call for gettext command may lead to use-after-freeEPSS 0.2%CVE-2022-20566HIGHIn l2cap_chan_put of l2cap_core, there is a possible use after free due to improper locking. This could lead to local escalation of privilegEPSS 0.2%CVE-2025-61842MEDIUMFormat Plugins | Use After Free (CWE-416)EPSS 0.2%