Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-27056HIGHUse After Free in DSP ServiceEPSS 0.1%CVE-2023-20664MEDIUMIn gz, there is a possible double free due to a use after free. This could lead to local escalation of privilege with System execution priviEPSS 0.1%CVE-2023-20608MEDIUMIn display drm, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System exeEPSS 0.1%CVE-2025-20780HIGHIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2023-40100HIGHIn discovery_thread of Dns64Configuration.cpp, there is a possible memory corruption due to a use after free. This could lead to local escalEPSS 0.1%CVE-2023-40131HIGHIn GpuService of GpuService.cpp, there is a possible use after free due to a race condition. This could lead to local escalation of privilegEPSS 0.1%CVE-2026-23787MEDIUMAn issue was discovered in DPU in Samsung Mobile Processor Exynos 1280, 2200, 1380, 1480, 2400, 1580, 2500, 1680, and 2600. A Use-After-FreeEPSS 0.1%CVE-2024-53015MEDIUMUse After Free in Computer VisionEPSS 0.1%CVE-2025-22409HIGHIn rfc_send_buf_uih of rfc_ts_frames.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to localEPSS 0.1%CVE-2024-27205HIGHthere is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional executionEPSS 0.1%CVE-2024-25985HIGHIn bigo_unlocked_ioctl of bigo.c, there is a possible UAF due to a missing bounds check. This could lead to local escalation of privilege wiEPSS 0.1%CVE-2023-43543MEDIUMUse After Free in AudioEPSS 0.1%CVE-2025-21474HIGHUse After Free in BTHOSTEPSS 0.1%CVE-2025-21456HIGHUse After Free in NPUEPSS 0.1%CVE-2025-32332HIGHIn multiple locations, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with EPSS 0.1%CVE-2024-34748HIGHIn _DevmemXReservationPageAddress of devicemem_server.c, there is a possible use-after-free due to improper casting. This could lead to locaEPSS 0.1%CVE-2025-21458HIGHUse After Free in NPUEPSS 0.1%CVE-2024-33040MEDIUMUse After Free in Camera DriverEPSS 0.1%CVE-2025-59617MEDIUMUse After Free in Computer VisionEPSS 0.1%CVE-2022-47371MEDIUMIn bt driver, there is a thread competition leads to early release of resources to be accessed. This could lead to local denial of service iEPSS 0.1%