Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2026-11072HIGHUse after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via a maliciEPSS 0.1%CVE-2025-21453HIGHUse After Free in GPS HLOS DriverEPSS 0.1%CVE-2025-21437HIGHUse After Free in Automotive Linux OSEPSS 0.1%CVE-2026-76957MEDIUMlibexpat before 2.8.4 lacks handler call depth tracking with custom encoding callbacks. Thus, a use-after-free can occur. NOTE: this is simiEPSS 0.1%CVE-2025-21436HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2022-36855MEDIUMA use after free vulnerability in iva_ctl driver prior to SMR Sep-2022 Release 1 allows attacker to cause memory access fault.EPSS 0.1%CVE-2022-20372HIGHIn exynos5_i2c_irq of (TBD), there is a possible out of bounds write due to a use after free. This could lead to local escalation of privileEPSS 0.1%CVE-2026-24917MEDIUMUAF vulnerability in the security module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%CVE-2026-20414MEDIUMIn imgsys, there is a possible escalation of privilege due to use after free. This could lead to local escalation of privilege if a maliciouEPSS 0.1%CVE-2025-27723MEDIUMUse after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Kernel may allow a denEPSS 0.1%CVE-2024-23697HIGHIn RGXCreateHWRTData_aux of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalaEPSS 0.1%CVE-2024-33034HIGHUse After Free in Graphics LinuxEPSS 0.1%CVE-2024-23696HIGHIn RGXCreateZSBufferKM of rgxta3d.c, there is a possible arbitrary code execution due to a use after free. This could lead to local escalatiEPSS 0.1%CVE-2026-7925HIGHUse after free in Chromoting in Google Chrome on Windows prior to 148.0.7778.96 allowed a local attacker to perform OS-level privilege escalEPSS 0.1%CVE-2024-45571HIGHUse After Free in WLAN Host CommunicationEPSS 0.1%CVE-2026-58751MEDIUMIn multiple functions of arm-smmu-v3.c, there is a possible use-after-free due to a logic error in the code. This could lead to local escalaEPSS 0.1%CVE-2024-38424HIGHUse After Free in GPSEPSS 0.1%CVE-2025-47359HIGHUse After Free in Secure ProcessorEPSS 0.1%CVE-2024-38419HIGHUse After Free in Automotive GPUEPSS 0.1%CVE-2025-47358HIGHUse After Free in Secure ProcessorEPSS 0.1%