Falhas do tipo CWE-416

5.142 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-52757MEDIUMGhidra < 12.1 - Heap-use-after-free in HighVariable::merge() during decompilationEPSS 0.2%CVE-2025-9020LOWPX4 PX4-Autopilot Mavlink Shell Closing mavlink_receiver.cpp handle_message_serial_control use after freeEPSS 0.2%CVE-2024-1395MEDIUMMali GPU Kernel Driver allows improper GPU memory processing operationsEPSS 0.2%CVE-2026-28933MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOEPSS 0.2%CVE-2026-50061HIGHA vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update EPSS 0.2%CVE-2026-19548MEDIUMBinutils: binutils: multiple use-after-free in add_archive_element via lto plugin processingEPSS 0.2%CVE-2026-76921MEDIUMUse After Free in WiresharkEPSS 0.2%CVE-2026-50060HIGHA vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 15), Solid Edge SE2026 (All versions < V226.0 Update EPSS 0.2%CVE-2026-65402MEDIUMA use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27,EPSS 0.2%CVE-2025-38500HIGHxfrm: interface: fix use-after-free after changing collect_md xfrm interfaceEPSS 0.2%CVE-2021-30337HIGHPossible use after free when process shell memory is freed using IOCTL call and process initialization is in progress in Snapdragon Auto, SnEPSS 0.2%CVE-2023-47857MEDIUMmultimedia camera has a UAF vulnerabilityEPSS 0.2%CVE-2023-49135MEDIUMmultimedia player has a UAF vulnerabilityEPSS 0.2%CVE-2024-56434MEDIUMUAF vulnerability in the device node access module Impact: Successful exploitation of this vulnerability may cause service exceptions of theEPSS 0.2%CVE-2023-48360MEDIUMmultimedia player has a UAF vulnerabilityEPSS 0.2%CVE-2026-84521MEDIUMA use after free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27,EPSS 0.2%CVE-2026-45251HIGHKernel use-after-free via file descriptor syscallsEPSS 0.2%CVE-2023-5091HIGHMali GPU Kernel Driver allows improper GPU processing operationsEPSS 0.2%CVE-2026-43808MEDIUMA use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.6 and iPadOS 26.6, macOS Tahoe 26.6, tvOEPSS 0.2%CVE-2026-58090HIGHUse-after-free in unix SOCK_STREAM message handlingEPSS 0.2%