Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-91790HIGHFoxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure VulnerabilityEPSS 0.1%CVE-2026-91793HIGHFoxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure VulnerabilityEPSS 0.1%CVE-2022-20552MEDIUMIn btif_a2dp_sink_command_ready of btif_a2dp_sink.cc, there is a possible out of bounds read due to a use after free. This could lead to locEPSS 0.1%CVE-2026-11623LOWtmux image.c image_free use after freeEPSS 0.1%CVE-2026-47588HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause a use-after-free condition by issuing a EPSS 0.1%CVE-2026-47589HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by EPSS 0.1%CVE-2026-47594HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by EPSS 0.1%CVE-2026-47587HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability where an unprivileged user could cause a use-after-free. A successful exploit oEPSS 0.1%CVE-2026-47590HIGHNVIDIA GPU Display Driver for Windows and Linux contains a vulnerability where an unprivileged user may cause a use-after-free condition by EPSS 0.1%CVE-2022-33225MEDIUMUse after free in Trusted Application EnvironmentEPSS 0.1%CVE-2023-28577MEDIUMMultiple Dmabuf Kernel Address UAF VulnerabilityEPSS 0.1%CVE-2022-20158MEDIUMIn bdi_put and bdi_unregister of backing-dev.c, there is a possible memory corruption due to a use after free. This could lead to local escaEPSS 0.1%CVE-2022-33245MEDIUMUse after free in WLANEPSS 0.1%CVE-2026-4737HIGHUse-After-Free Vulnerability in No-Chicken/Echo-MateEPSS 0.1%CVE-2022-42754MEDIUMIn npu driver, there is a memory corruption due to a use after free. This could lead to local denial of service in kernel.EPSS 0.1%CVE-2022-25723HIGHMemory corruption in multimedia due to use after free during callback registration failure in Snapdragon MobileEPSS 0.1%CVE-2025-0031MEDIUMA use after free in the SEV firmware could allow a malicous hypervisor to activate a migrated guest with the SINGLE_SOCKET policy on a diffeEPSS 0.1%CVE-2022-39853MEDIUMA use after free vulnerability in perf-mgr driver prior to SMR Oct-2022 Release 1 allows attacker to cause memory access fault.EPSS 0.1%CVE-2023-33094HIGHUse After Free in Linux GraphicsEPSS 0.1%CVE-2023-33114HIGHUse after free in Neural Processing UnitEPSS 0.1%