Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-21968HIGHdrm/amd/display: Fix slab-use-after-free on hdcp_workEPSS 0.2%CVE-2026-84895HIGHIn proxygen from v2026.04.06.00 until v2026.09.28.00, QuicWtSession::closeSession accesses its member fields after calling the base QuicWtSeEPSS 0.2%CVE-2023-52935HIGHmm/khugepaged: fix ->anon_vma raceEPSS 0.2%CVE-2022-49921HIGHnet: sched: Fix use after free in red_enqueue()EPSS 0.2%CVE-2025-15538MEDIUMOpen Asset Import Library Assimp LWOMaterial.cpp FindUVChannels use after freeEPSS 0.2%CVE-2024-27217MEDIUMMSDP has a use after free vulnerabilityEPSS 0.2%CVE-2026-1289HIGHPDF File Parsing Vulnerabilities in Certain Autodesk Desktop ProductsEPSS 0.2%CVE-2026-33018HIGHlibsixel: Use-After-Free in load_gif()EPSS 0.2%CVE-2026-55406MEDIUMBuffa: Use-After-Free in OwnedView via Unsound 'static Lifetime Promotion in DerefEPSS 0.2%CVE-2024-56635HIGHnet: avoid potential UAF in default_operstate()EPSS 0.2%CVE-2023-41093LOWLoss of confidentiality due to potential race condition in Bluetooth controller Connection_Handle reuseEPSS 0.2%CVE-2025-4878LOWLibssh: use of uninitialized variable in privatekey_from_file()EPSS 0.2%CVE-2023-42892HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Ventura 13.6.3, macOS Sonoma 14.2, macOS EPSS 0.2%CVE-2023-53023HIGHnet: nfc: Fix use-after-free in local_cleanup()EPSS 0.2%CVE-2023-53021HIGHnet/sched: sch_taprio: fix possible use-after-freeEPSS 0.2%CVE-2026-34734HIGHHDF5: H5T__conv_struct Use After FreeEPSS 0.2%CVE-2026-53009HIGHice: fix double-free of tx_buf skbEPSS 0.2%CVE-2026-87628HIGHUse after free in Cast in Google Chrome prior to 153.0.8010.36 allowed an adjacent attacker to potentially execute arbitrary code outside thEPSS 0.2%CVE-2026-12029HIGHUse after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer proceEPSS 0.2%CVE-2021-47669HIGHcan: vxcan: vxcan_xmit: fix use after free bugEPSS 0.2%