Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2023-4134MEDIUMKernel: cyttsp4_core: use-after-free in cyttsp4_watchdog_work()EPSS 0.2%CVE-2026-14760MEDIUMradareorg radare2 regprofile disasm.c r_core_seek_arch_bits use after freeEPSS 0.2%CVE-2025-22036HIGHexfat: fix random stack corruption after get_blockEPSS 0.2%CVE-2025-5036HIGHRFA File Parsing Use-After-Free VulnerabilityEPSS 0.2%CVE-2026-14788MEDIUMradareorg radare2 cfile.c r_core_bin_load use after freeEPSS 0.2%CVE-2024-3759MEDIUMHmdfs has a use after free vulnerabilityEPSS 0.2%CVE-2026-50257HIGHXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestroyfence()EPSS 0.2%CVE-2025-69627HIGHNitro PDF Pro for Windows 14.41.1.4 contains a heap use-after-free vulnerability in the implementation of the JavaScript method this.mailDocEPSS 0.2%CVE-2025-1704MEDIUMComponentInstaller Modification in ComponentInstaller in Google ChromeOS 15823.23.0 on Chromebooks allows enrolled users with local access tEPSS 0.2%CVE-2025-60464HIGHA use-after-free in the gf_sei_load_from_state_internal function (/filters/sei_load.c) of GPAC Project/MP4Box before 26.02.0 allows attackerEPSS 0.2%CVE-2023-2985MEDIUMA use after free flaw was found in hfsplus_put_super in fs/hfsplus/super.c in the Linux Kernel. This flaw could allow a local user to cause EPSS 0.2%CVE-2023-0590—A use-after-free flaw was found in qdisc_graft in net/sched/sch_api.c in the Linux Kernel due to a race problem. This flaw leads to a denialEPSS 0.2%CVE-2023-21125HIGHIn btif_hh_hsdata_rpt_copy_cb of bta_hh.cc, there is a possible way to corrupt memory due to a use after free. This could lead to local escaEPSS 0.2%CVE-2026-50261HIGHXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangecounter()EPSS 0.2%CVE-2026-50260HIGHXorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter()EPSS 0.2%CVE-2026-20637MEDIUMA use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.3 and iPadEPSS 0.2%CVE-2025-22024MEDIUMnfsd: fix management of listener transportsEPSS 0.2%CVE-2026-87825HIGHzstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free of Compression and Decompression DictionariesEPSS 0.2%CVE-2025-21893HIGHkeys: Fix UAF in key_put()EPSS 0.2%CVE-2025-21968HIGHdrm/amd/display: Fix slab-use-after-free on hdcp_workEPSS 0.2%