Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CWE-401 (在移除最后引用时对内存的释放不恰当(内存泄露)) — Vulnerability Class 292

292 vulnerabilities classified as CWE-401 (在移除最后引用时对内存的释放不恰当(内存泄露)). AI Chinese analysis included.

CWE-401 represents a memory management weakness where software fails to release allocated memory after its effective lifetime, leading to resource exhaustion. This defect typically manifests as a denial-of-service condition rather than direct code execution, as the continuous accumulation of unreleased memory gradually depletes system resources. Attackers exploit this by triggering repeated allocations, causing the application or host to crash when memory limits are reached. Developers prevent this by implementing rigorous memory lifecycle management, ensuring every allocation has a corresponding deallocation call. Utilizing automated static analysis tools helps identify leaks during development, while adopting garbage-collected languages or smart pointers in C++ can significantly reduce the risk. Regular memory profiling during testing further ensures that allocated resources are properly returned to the system, maintaining application stability and preventing resource starvation.

MITRE CWE Description
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
Common Consequences (2)
Availability DoS: Crash, Exit, or Restart, DoS: Instability, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory)
Most memory leaks result in general product reliability problems, but if an attacker can intentionally trigger a memory leak, the attacker might be able to launch a denial of service attack (by crashing or hanging the program) or take advantage of other unexpected program behavior resulting from a l…
Other Reduce Performance
Mitigations (3)
Implementation Choose a language or tool that provides automatic memory management, or makes manual memory management less error-prone. For example, glibc in Linux provides protection against free of invalid pointers. When using Xcode to target OS X or iOS, enable automatic reference counting (ARC) [REF-391]. To help correctly and consistently manage memory when programming in C++, consider using a smart pointer…
Architecture and Design Use an abstraction library to abstract away risky APIs. Not a complete solution.
Architecture and Design, Build and Compilation Consider using the Boehm-Demers-Weiser garbage collector (bdwgc), which can help avoid leaks.
Effectiveness: Moderate
Examples (1)
The following C function leaks a block of allocated memory if the call to read() does not return the expected number of bytes:
char* getBlock(int fd) { char* buf = (char*) malloc(BLOCK_SIZE); if (!buf) { return NULL; } if (read(fd, buf, BLOCK_SIZE) != BLOCK_SIZE) { return NULL; } return buf; }
Bad · C
CVE ID Title CVSS Severity Published
CVE-2023-29163 BIG-IP UDP Profile vulnerability — BIG-IP 7.5 High 2023-05-03
CVE-2023-21666 Improper Release of Memory Before Removing Last Reference (`Memory Leak`) in Graphics — Snapdragon 8.4 High 2023-05-02
CVE-2023-28982 Junos OS and Junos OS Evolved: In a BGP rib sharding scenario when a route is frequently updated an rpd memory leak will occur — Junos OS 7.5 High 2023-04-17
CVE-2023-24511 On affected platforms running Arista EOS with SNMP configured, a specially crafted packet can cause a memory leak in the snmpd process. — EOS 5.3 Medium 2023-04-12
CVE-2023-1074 Linux kernel 安全漏洞 — kernel 5.5 - 2023-03-27
CVE-2023-28096 OpenSIPS has memory leak in cJSON lib — opensips 4.5 Medium 2023-03-15
CVE-2023-25566 GSS-NTLMSSP vulnerable to memory leak when parsing usernames — gss-ntlmssp 7.5 High 2023-02-14
CVE-2023-22395 Junos OS: In an MPLS scenario the processing of specific packets to the device causes a buffer leak and ultimately a loss of connectivity — Junos OS 6.5 Medium 2023-01-12
CVE-2023-22406 Junos OS and Junos OS Evolved: A memory leak which will ultimately lead to an rpd crash will be observed when a peer interface flaps continuously in a Segment Routing scenario using OSPF — Junos OS 6.5 Medium 2023-01-12
CVE-2023-22410 Junos OS: MX Series with MPC10/MPC11: When Suspicious Control Flow Detection (scfd) is enabled and an attacker is sending specific traffic, this causes a memory leak. — Junos OS 7.5 High 2023-01-12
CVE-2023-22414 Junos OS: PTX Series and QFX10000 Series: An FPC memory leak is observed when specific EVPN VXLAN Multicast packets are processed — Junos OS 6.5 Medium 2023-01-12
CVE-2023-22417 Junos OS: SRX Series: A memory leak might be observed in IPsec VPN scenario leading to an FPC crash — Junos OS 7.5 High 2023-01-12
CVE-2022-3629 Linux Kernel af_vsock.c vsock_connect memory leak — Kernel 2.6 Low 2022-10-21
CVE-2022-3633 Linux Kernel transport.c j1939_session_destroy memory leak — Kernel 3.5 Low 2022-10-21
CVE-2022-3577 Linux kernel 缓冲区错误漏洞 — Kernel 7.8 - 2022-10-20
CVE-2022-41832 BIG-IP SIP vulnerability CVE-2022-41832 — BIG-IP 7.5 High 2022-10-19
CVE-2022-41624 BIG-IP iRules vulnerability CVE-2022-41624 — BIG-IP 7.5 High 2022-10-19
CVE-2022-31222 Dell BIOS 安全漏洞 — CPG BIOS 2.3 Low 2022-09-12
CVE-2021-3574 ImageMagick 安全漏洞 — ImageMagick 5.5 - 2022-08-26
CVE-2021-4213 Linux jss 安全漏洞 — JSS 7.5 - 2022-08-24
CVE-2021-3905 Open vSwitch 安全漏洞 — openvswitch (ovs) 7.5 - 2022-08-23
CVE-2021-33645 openEuler 安全漏洞 — libtar 6.5 - 2022-08-09
CVE-2021-33646 openEuler 安全漏洞 — libtar 6.5 - 2022-08-09
CVE-2022-1012 Linux kernel 安全漏洞 — Kernel 8.2 - 2022-08-05
CVE-2022-1651 Linux kernel 安全漏洞 — Kernel 7.1 - 2022-07-26
CVE-2022-22209 Junos OS: RIB and PFEs can get out of sync due to a memory leak caused by interface flaps or route churn — Junos OS 7.5 High 2022-07-20
CVE-2022-22205 Junos OS: SRX Series: An FPC memory leak can occur in an APBR scenario — Junos OS 7.5 High 2022-07-20
CVE-2022-22204 Junos OS: MX Series and SRX Series: When receiving a specific SIP packets stale call table entries are created which eventually leads to a DoS for all SIP traffic — Junos OS 5.3 Medium 2022-07-20
CVE-2022-20785 ClamAV HTML Scanning Memory Leak Vulnerability Affecting Cisco Products: April 2022 — Cisco AMP for Endpoints 7.5 High 2022-05-04
CVE-2022-1515 MATIO 安全漏洞 — matio 5.5 - 2022-05-02

Vulnerabilities classified as CWE-401 (在移除最后引用时对内存的释放不恰当(内存泄露)) represent 292 CVEs. The CWE taxonomy describes the weakness; review individual CVEs for product-specific impact.