目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-401 在移除最后引用时对内存的释放不恰当(内存泄露) 类漏洞列表 292

CWE-401 在移除最后引用时对内存的释放不恰当(内存泄露) 类弱点 292 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-401属于内存管理漏洞,指程序在内存使用完毕后未正确释放,导致资源无法回收。攻击者通常利用此缺陷通过反复分配内存耗尽系统资源,引发拒绝服务或导致程序崩溃。开发者应避免此类问题,需确保在内存生命周期结束时调用释放函数,并采用智能指针或自动内存管理工具,严格跟踪内存分配与释放状态,防止内存泄漏。

MITRE CWE 官方描述
CWE:CWE-401 Missing Release of Memory after Effective Lifetime 英文:The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.
常见影响 (2)
Availability DoS: Crash, Exit, or Restart, DoS: Instability, DoS: Resource Consumption (CPU), DoS: Resource Consumption (Memory)
Most memory leaks result in general product reliability problems, but if an attacker can intentionally trigger a memory leak, the attacker might be able to launch a denial of service attack (by crashing or hanging the program) or take advantage of other unexpected program behavior resulting from a l…
Other Reduce Performance
缓解措施 (3)
Implementation Choose a language or tool that provides automatic memory management, or makes manual memory management less error-prone. For example, glibc in Linux provides protection against free of invalid pointers. When using Xcode to target OS X or iOS, enable automatic reference counting (ARC) [REF-391]. To help correctly and consistently manage memory when programming in C++, consider using a smart pointer…
Architecture and Design Use an abstraction library to abstract away risky APIs. Not a complete solution.
Architecture and Design, Build and Compilation Consider using the Boehm-Demers-Weiser garbage collector (bdwgc), which can help avoid leaks.
Effectiveness: Moderate
代码示例 (1)
The following C function leaks a block of allocated memory if the call to read() does not return the expected number of bytes:
char* getBlock(int fd) { char* buf = (char*) malloc(BLOCK_SIZE); if (!buf) { return NULL; } if (read(fd, buf, BLOCK_SIZE) != BLOCK_SIZE) { return NULL; } return buf; }
Bad · C
CVE ID 标题 CVSS 风险等级 Published
CVE-2025-25057 OpenHarmony 安全漏洞 — OpenHarmony 3.3 Low 2025-04-07
CVE-2025-3198 GNU Binutils(GNU Binary Utilities) 安全漏洞 — Binutils 3.3 Low 2025-04-04
CVE-2024-6875 Red Hat Infinispan 安全漏洞 6.5 Medium 2025-03-28
CVE-2025-29910 CryptoLib 安全漏洞 — CryptoLib 7.5 - 2025-03-17
CVE-2024-9135 Arista EOS 安全漏洞 — EOS 5.3 Medium 2025-03-04
CVE-2025-20011 OpenHarmony 安全漏洞 — OpenHarmony 3.3 Low 2025-03-04
CVE-2025-1816 FFmpeg 安全漏洞 — FFmpeg 4.3 Medium 2025-03-02
CVE-2025-1634 Red Hat Quarkus 安全漏洞 7.5 High 2025-02-26
CVE-2025-25199 Microsoft go-crypto-winnative 安全漏洞 — go-crypto-winnative 7.5 High 2025-02-12
CVE-2025-1152 GNU Binutils 安全漏洞 — Binutils 3.1 Low 2025-02-10
CVE-2025-1151 GNU Binutils 安全漏洞 — Binutils 3.1 Low 2025-02-10
CVE-2025-1150 GNU Binutils 安全漏洞 — Binutils 3.1 Low 2025-02-10
CVE-2025-1149 GNU Binutils 安全漏洞 — Binutils 3.1 Low 2025-02-10
CVE-2025-1148 GNU Binutils 安全漏洞 — Binutils 3.1 Low 2025-02-10
CVE-2025-21091 F5 BIG-IP 安全漏洞 — BIG-IP 7.5 High 2025-02-05
CVE-2025-21599 Juniper Networks Junos OS Evolved 安全漏洞 — Junos OS Evolved 7.5 High 2025-01-09
CVE-2024-53984 Nanopb 安全漏洞 — nanopb 4.3 Medium 2024-12-02
CVE-2024-47493 Juniper Networks Junos OS 安全漏洞 — Junos OS 6.5 Medium 2024-10-11
CVE-2024-8376 Eclipse Mosquitto 安全漏洞 — Mosquitto 9.1 - 2024-10-11
CVE-2024-43696 OpenHarmony 安全漏洞 — OpenHarmony 3.3 Low 2024-10-08
CVE-2024-20304 Cisco IOS XR 安全漏洞 — Cisco IOS XR Software 8.6 High 2024-09-11
CVE-2024-7884 Rust Canister Development Kit 安全漏洞 — ic-cdk 7.5 High 2024-09-05
CVE-2024-41172 Apache CXF 安全漏洞 — Apache CXF 7.5 - 2024-07-19
CVE-2024-39550 Juniper Networks Junos OS 安全漏洞 — Junos OS 6.5 Medium 2024-07-11
CVE-2024-39549 Juniper Networks Junos OS和Juniper Networks Junos OS Evolved 安全漏洞 — Junos OS 7.5 High 2024-07-11
CVE-2024-39539 Juniper Networks Junos OS 安全漏洞 — Junos OS 5.3 Medium 2024-07-11
CVE-2024-39536 Juniper Networks Junos OS和Juniper Networks Junos OS Evolved 安全漏洞 — Junos OS 5.3 Medium 2024-07-11
CVE-2024-3653 Red Hat Undertow 安全漏洞 5.3 Medium 2024-07-08
CVE-2024-5294 D-Link DIR-3040 安全漏洞 — DIR-3040 6.5AI Medium AI 2024-05-23
CVE-2024-4435 Stable Structures 安全漏洞 — ic-stable-structures 5.9 Medium 2024-05-21

CWE-401(在移除最后引用时对内存的释放不恰当(内存泄露)) 是常见的弱点类别,本平台收录该类弱点关联的 292 条 CVE 漏洞。