Falhas do tipo CWE-416

5.142 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-92473MEDIUMGPAC BIFS commands.c gf_sg_command_del use after freeEPSS 0.2%CVE-2025-22411HIGHIn process_service_attr_rsp of sdp_discovery.cc, there is a possible use after free due to a logic error in the code. This could lead to remEPSS 0.2%CVE-2026-90825MEDIUMGPAC MP4Box base_scenegraph.c gf_node_unregister use after freeEPSS 0.2%CVE-2026-92474MEDIUMGPAC Proto Link mpeg4_inline.c gf_inline_get_proto_lib use after freeEPSS 0.2%CVE-2026-92472MEDIUMGPAC MP4Box base_scenegraph.c gf_node_deactivate_ex use after freeEPSS 0.2%CVE-2026-58083HIGHUse-after-free in kqueue copy-on-forkEPSS 0.2%CVE-2026-13595MEDIUMUtil-linux: util-linux: heap use-after-free in libblkid nested partition probingEPSS 0.2%CVE-2024-39831MEDIUMAccessTokenManager has an use after free vulnerabilityEPSS 0.2%CVE-2024-47891HIGHGPU DDK - Exploitable double free on PTL_STREAM_DESC object in the kernel function TLServerCloseStreamKM due to a race conditionEPSS 0.2%CVE-2026-2656LOWChaiScript type_info.hpp bare_equal use after freeEPSS 0.2%CVE-2026-24200HIGHNVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. AEPSS 0.2%CVE-2026-47331HIGHUse-after-free in Ubuntu Linux AppArmor notification handlingEPSS 0.2%CVE-2025-58411HIGHGPU DDK - Reservation::psMappedPMR can change while used by a freelist -> UAFEPSS 0.2%CVE-2024-12837HIGHGPU DDK - Exploitable kernel double free on apsFenceSyncCheckpoints allocated with arbitrary sizeEPSS 0.2%CVE-2022-50384HIGHstaging: vme_user: Fix possible UAF in tsi148_dma_list_addEPSS 0.2%CVE-2024-47898HIGHGPU DDK - PVRSRVDeviceSyncOpen use-after-free conditionEPSS 0.2%CVE-2026-2655LOWChaiScript chaiscript_defines.hpp operator use after freeEPSS 0.2%CVE-2024-47899HIGHGPU DDK - PVRSRVDeviceServicesOpen use-after-free conditionEPSS 0.2%CVE-2026-34196HIGHGPU DDK - UAF read and/or write of arbitrary physical memory due to integer truncation in PMRDevPhysAddrOSMemEPSS 0.2%CVE-2025-23402HIGHA vulnerability has been identified in Teamcenter Visualization V14.3 (All versions < V14.3.0.13), Teamcenter Visualization V2312 (All versiEPSS 0.2%