Falhas do tipo CWE-416

5.143 resultados

Uso após liberação de memória

Ocorre quando o código tenta acessar (ler ou escrever) um bloco de memória que já foi liberado (free, delete). O programa mantém um ponteiro para a memória, mas o sistema operacional pode reatribuir essa região para outro uso, causando corrupção de dados, travamento ou execução de código arbitrário.

Exemplo

Um servidor web aloca memória para armazenar dados de sessão do usuário, depois libera essa memória quando a sessão encerra. Se uma thread continuar tentando acessar essa sessão após a liberação, pode ler dados de outra sessão ou sobrescrever dados críticos de outro processo.

Como mitigar

Sempre anule ponteiros após liberar memória (ptr = NULL), use variáveis de controle para rastrear estado de alocação, implemente gerenciamento automático de memória quando possível (smart pointers em C++), e execute testes com sanitizers (AddressSanitizer, Valgrind) durante desenvolvimento e CI/CD.

CVE-2025-22407MEDIUMIn hidd_check_config_done of hidd_conn.cc, there is a possible way to execute arbitrary code due to a use after free. This could lead to locEPSS 0.1%CVE-2023-48353MEDIUMIn vsp driver, there is a possible use after free due to a logic error. This could lead to local denial of service with System execution priEPSS 0.1%CVE-2018-9439HIGHIn __unregister_prot_hook and packet_release of af_packet.c, there is a possible use-after-free due to improper locking. This could leadEPSS 0.1%CVE-2025-20787MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2025-20773MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2025-20804MEDIUMIn dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor hEPSS 0.1%CVE-2024-32927HIGHIn sendDeviceState_1_6 of RadioExt.cpp, there is a possible use after free due to improper locking. This could lead to local escalation of pEPSS 0.1%CVE-2025-20802MEDIUMIn geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious aEPSS 0.1%CVE-2025-20806MEDIUMIn dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor hEPSS 0.1%CVE-2025-20770MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2025-20785MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2025-20775MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2024-40669HIGHIn TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additionEPSS 0.1%CVE-2025-20772MEDIUMIn display, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actEPSS 0.1%CVE-2024-40670HIGHIn TBD of TBD, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additionEPSS 0.1%CVE-2022-39847MEDIUMUse after free vulnerability in set_nft_pid and signal_handler function of NFC driver prior to SMR Oct-2022 Release 1 allows attackers to peEPSS 0.1%CVE-2025-20805MEDIUMIn dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if a malicious actor hEPSS 0.1%CVE-2024-47017HIGHIn ufshc_scsi_cmd of ufs.c, there is a possible stack variable use after free due to a use after free. This could lead to local escalation oEPSS 0.1%CVE-2025-47339HIGHUse After Free in HLOSEPSS 0.1%CVE-2025-58307MEDIUMUAF vulnerability in the screen recording framework module. Impact: Successful exploitation of this vulnerability may affect availability.EPSS 0.1%