Falhas do tipo CWE-416

5.142 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-6973HIGHUse After Free vulnerability exists in the JT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025EPSS 0.2%CVE-2026-15194MEDIUMOpen5GS AMF context.c amf_context_final use after freeEPSS 0.2%CVE-2023-53219HIGHmedia: netup_unidvb: fix use-after-free at del_timer()EPSS 0.2%CVE-2023-53316HIGHdrm/msm/dp: Free resources after unregistering themEPSS 0.2%CVE-2024-38402HIGHUse After Free in DSP ServicesEPSS 0.2%CVE-2025-6971HIGHUse After Free vulnerability exists in the CATPRODUCT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025EPSS 0.2%CVE-2026-5940HIGHFoxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution VulnerabilityEPSS 0.2%CVE-2023-53311HIGHnilfs2: fix use-after-free of nilfs_root in dirtying inodes via iputEPSS 0.2%CVE-2022-50408HIGHwifi: brcmfmac: fix use-after-free bug in brcmf_netdev_start_xmit()EPSS 0.2%CVE-2022-50422HIGHscsi: libsas: Fix use-after-free bug in smp_execute_task_sg()EPSS 0.2%CVE-2023-53307HIGHrbd: avoid use-after-free in do_rbd_add() when rbd_dev_create() failsEPSS 0.2%CVE-2026-6424MEDIUMUse-after-free vulnerability in ESET security products for LinuxEPSS 0.2%CVE-2025-7042HIGHUse After Free vulnerability exists in the IPT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025EPSS 0.2%CVE-2023-53282HIGHscsi: lpfc: Fix use-after-free KFENCE violation during sysfs firmware writeEPSS 0.2%CVE-2025-65955MEDIUMImageMagick has a use-after-free/double-free risk in Options::fontFamily when clearing familyEPSS 0.2%CVE-2026-3979MEDIUMquickjs-ng quickjs quickjs.c js_iterator_concat_return use after freeEPSS 0.2%CVE-2022-50378HIGHdrm/meson: reorder driver deinit sequence to fix use-after-free bugEPSS 0.2%CVE-2022-49919HIGHnetfilter: nf_tables: release flow rule object from commit pathEPSS 0.2%CVE-2026-18785MEDIUMo6 open62541 client_types_custom.c UA_Client_getRemoteDataTypes use after freeEPSS 0.2%CVE-2022-50417HIGHdrm/panfrost: Fix GEM handle creation ref-countingEPSS 0.2%