Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-20506MEDIUMIn Audio HAL, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicEPSS 0.1%CVE-2026-20517MEDIUMIn geniezone, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a malicEPSS 0.1%CVE-2026-24927MEDIUMOut-of-bounds access vulnerability in the frequency modulation module. Impact: Successful exploitation of this vulnerability may affect avaiEPSS 0.1%CVE-2024-34747HIGHIn DevmemXIntMapPages of devicemem_server.c, there is a possible use-after-free due to a logic error in the code. This could lead to local eEPSS 0.1%CVE-2026-86423MEDIUMImageMagick before 7.1.2-30 Heap-use-after-free via GetListEPSS 0.1%CVE-2022-25722MEDIUMInformation Exposure in DSP ServicesEPSS 0.1%CVE-2024-45583MEDIUMUse After Free in Secure ProcessorEPSS 0.1%CVE-2026-12285MEDIUMMali GPU Kernel Driver allows access to already freed memoryEPSS 0.1%CVE-2026-47598HIGHNVIDIA GPU Display Driver for Linux contains a vulnerability in the open-source kernel module event delivery path where an unprivileged locaEPSS 0.1%CVE-2024-45562MEDIUMUse After Free in HLOSEPSS 0.1%CVE-2024-23381HIGHUse After Free in Graphics LinuxEPSS 0.1%CVE-2024-21468HIGHUse After Free in KernelEPSS 0.1%CVE-2024-33028HIGHUse After Free in Automotive TelematicsEPSS 0.1%CVE-2024-21472HIGHUse After Free in KernelEPSS 0.1%CVE-2023-43547HIGHUse After Free in Automotive MultimediaEPSS 0.1%CVE-2026-20515MEDIUMIn gpu, there is a possible system crash due to use after free. This could lead to local information disclosure with User execution privilegEPSS 0.1%CVE-2024-21471HIGHUse After Free in Graphics LinuxEPSS 0.1%CVE-2023-43546HIGHUse After Free in Automotive MultimediaEPSS 0.1%CVE-2024-33023HIGHUse After Free in Graphics LinuxEPSS 0.1%CVE-2023-43514HIGHUse After Free in DSP ServicesEPSS 0.1%