Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2022-20571MEDIUMIn extract_metadata of dm-android-verity.c, there is a possible way to corrupt kernel memory due to a use after free. This could lead to locEPSS 0.2%CVE-2025-59734HIGHHeap-buffer-overflow write in FFmpeg SANM process_ftchEPSS 0.2%CVE-2022-20554MEDIUMIn removeEventHubDevice of InputDevice.cpp, there is a possible OOB read due to a use after free. This could lead to local escalation of priEPSS 0.2%CVE-2026-45782HIGHCloud Hypervisor: Use-after-free in virtio-block Async I/O CompletionEPSS 0.2%CVE-2023-20928HIGHIn binder_vma_close of binder.c, there is a possible use after free due to improper locking. This could lead to local escalation of privilegEPSS 0.2%CVE-2024-54030MEDIUMCommunication_dsoftbus has an UAF vulnerabilityEPSS 0.2%CVE-2026-10002HIGHUse after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a craEPSS 0.2%CVE-2022-42520MEDIUMIn ServiceInterface::HandleRequest of serviceinterface.cpp, there is a possible use after free. This could lead to local escalation of priviEPSS 0.2%CVE-2026-56412MEDIUMlibexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls frEPSS 0.2%CVE-2026-11692HIGHUse after free in Read Anything in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process EPSS 0.2%CVE-2026-11700HIGHUse after free in Tracing in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potEPSS 0.2%CVE-2024-30378MEDIUMJunos OS: MX Series: bbe-smgd process crash upon execution of specific CLI commandsEPSS 0.2%CVE-2026-11679HIGHUse after free in Codecs in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer procEPSS 0.2%CVE-2024-0147MEDIUMNVIDIA GPU display driver for Windows and Linux contains a vulnerability where referencing memory after it has been freed can lead to denialEPSS 0.2%CVE-2022-20524HIGHIn compose of Vibrator.cpp, there is a possible arbitrary code execution due to a use after free. This could lead to local escalation of priEPSS 0.2%CVE-2023-49676MEDIUMCODESYS: Use after free vulnerability through corrupted project filesEPSS 0.2%CVE-2024-47040CRITICALUse After Free in the android.hardware.radio.sap.ISap/slot2 serviceEPSS 0.2%CVE-2025-8045MEDIUMMali GPU Kernel Driver allows improper GPU processing operationsEPSS 0.2%CVE-2026-49496MEDIUMGhidra < 12.1 - Heap-Use-After-Free in SleighBuilder::generatePointerAdd via Vector ReallocationEPSS 0.2%CVE-2026-27813MEDIUMEVerest has use-after-free in auth timeout timer via race conditionEPSS 0.2%