Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2023-6143HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2026-10014HIGHUse after free in WebMIDI in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer proEPSS 0.2%CVE-2026-42958HIGHUse After Free in Labcenter ProteusEPSS 0.2%CVE-2026-23401HIGHKVM: x86/mmu: Drop/zap existing present SPTE even when creating an MMIO SPTEEPSS 0.2%CVE-2026-40311MEDIUMImageMagick: Heap-use-after-free via XMP profile could result in a crash when printing valuesEPSS 0.2%CVE-2024-4607HIGHMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2025-60471MEDIUMA use-after-free in the gf_filter_pid_reconfigure_task_discard function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 alEPSS 0.2%CVE-2026-39316MEDIUMCUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointerEPSS 0.2%CVE-2026-10012HIGHUse after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentEPSS 0.2%CVE-2026-16147MEDIUMit82xx2 USB device controller submits incomplete OUT transfer buffers, causing use-after-free and event-list corruptionEPSS 0.2%CVE-2023-28469MEDIUMAn issue was discovered in the Arm Mali GPU Kernel Driver. A non-privileged user can make improper GPU processing operations to gain access EPSS 0.2%CVE-2026-47586MEDIUMNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability in the kernel module where an attacker could cause a use-after-freeEPSS 0.2%CVE-2024-28951MEDIUMArkcompiler runtime has a use after free vulnerabilityEPSS 0.2%CVE-2022-20540HIGHIn SurfaceFlinger::doDump of SurfaceFlinger.cpp, there is possible arbitrary code execution due to a use after free. This could lead to locaEPSS 0.2%CVE-2026-31419HIGHnet: bonding: fix use-after-free in bond_xmit_broadcast()EPSS 0.2%CVE-2026-28529HIGHcryptodev-linux <= 1.14 get_userbuf Use After Free LPEEPSS 0.2%CVE-2022-20571MEDIUMIn extract_metadata of dm-android-verity.c, there is a possible way to corrupt kernel memory due to a use after free. This could lead to locEPSS 0.2%CVE-2022-20514MEDIUMIn acquireFabricatedOverlayIterator, nextFabricatedOverlayInfos, and releaseFabricatedOverlayIterator of Idmap2Service.cpp, there is a possiEPSS 0.2%CVE-2026-71226HIGHLibkcapi: memory corruption via uncanceled aio requests on error in libkcapi's one-shot aio pathEPSS 0.2%CVE-2022-20554MEDIUMIn removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of priEPSS 0.2%