Falhas do tipo CWE-416

5.138 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-24301LOWArkcompiler Ets Runtime has an UAF vulnerabilityEPSS 0.2%CVE-2025-20091LOWCommunication Dsoftbus has an UAF vulnerabilityEPSS 0.2%CVE-2026-7349HIGHUse after free in Cast in Google Chrome prior to 147.0.7727.138 allowed an attacker on the local network segment to execute arbitrary code iEPSS 0.2%CVE-2026-57589HIGHsys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-afEPSS 0.2%CVE-2026-0001MEDIUMMali GPU Kernel Driver allows access to already freed memoryEPSS 0.2%CVE-2025-43478MEDIUMA use after free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.2, macOS Sonoma 14.8.2, macOEPSS 0.2%CVE-2025-20626LOWArkcompiler Ets Runtime has an UAF vulnerabilityEPSS 0.2%CVE-2026-11656HIGHUse after free in ServiceWorker in Google Chrome prior to 149.0.7827.103 allowed an attacker who convinced a user to install a malicious extEPSS 0.2%CVE-2025-23409LOWCommunication Dsoftbus has an UAF vulnerabilityEPSS 0.2%CVE-2023-6363MEDIUMMali GPU Kernel Driver allows improper GPU processing operationsEPSS 0.2%CVE-2025-23414LOWArkcompiler Ets Runtime has an UAF vulnerabilityEPSS 0.2%CVE-2026-6040MEDIUMHeap use-after-free in ODF number-format blank-width parsingEPSS 0.2%CVE-2026-49422HIGHUse-after-free in TCP RACK stack option handlerEPSS 0.2%CVE-2025-61864HIGHA use after free vulnerability exists in VS6ComFile!load_link_inf of V-SFT v6.2.7.0 and earlier. Opening specially crafted V-SFT files may lEPSS 0.2%CVE-2026-92472MEDIUMGPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after freeEPSS 0.2%CVE-2026-92474MEDIUMGPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after freeEPSS 0.2%CVE-2026-43684HIGHA use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, macOS Golden Gate 27,EPSS 0.2%CVE-2024-39831MEDIUMAccessTokenManager has an use after free vulnerabilityEPSS 0.2%CVE-2026-90578MEDIUMGPAC MP4Box list.c gf_list_count use after freeEPSS 0.2%CVE-2026-58083HIGHUse-after-free in kqueue copy-on-forkEPSS 0.2%