目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CWE-416 释放后使用 类漏洞列表 3237

CWE-416 释放后使用 类弱点 3237 条 CVE 漏洞汇总,含 AI 中文分析。

CWE-416 释放后使用是一种内存安全漏洞,指程序在释放内存后仍引用该内存区域。攻击者常利用此缺陷,通过重新分配内存并控制其内容,诱导程序执行恶意代码或读取敏感数据,从而引发远程代码执行或信息泄露。开发者应避免此类风险,确保在指针置空前彻底解除引用,采用智能指针等自动内存管理机制,并严格验证内存生命周期,防止悬空指针操作。

MITRE CWE 官方描述
CWE:CWE-416 Use After Free 英文:产品在内存被释放后重新使用或引用该内存。在此之后,该内存可能会被重新分配并保存到另一个指针中,而原始指针则指向新分配内存中的某个位置。由于内存“属于”操作新指针的代码,因此使用原始指针的任何操作均不再有效。
常见影响 (4)
IntegrityModify Memory
The use of previously freed memory may corrupt valid data, if the memory area in question has been allocated and used properly elsewhere.
AvailabilityDoS: Crash, Exit, or Restart
If chunk consolidation occurs after the use of previously freed data, the process may crash when invalid data is used as chunk information.
ConfidentialityRead Memory
Read operations on freed memory can sometimes leak sensitive information instead of causing a crash
Integrity, Confidentiality, AvailabilityExecute Unauthorized Code or Commands
If malicious data is entered before chunk consolidation can take place, it may be possible to take advantage of a write-what-where primitive to execute arbitrary code. If the newly allocated data happens to hold a class, in C++ for example, various function pointers may be scattered within the heap …
缓解措施 (2)
Architecture and DesignChoose a language that provides automatic memory management.
ImplementationWhen freeing pointers, be sure to set them to NULL once they are freed. However, the utilization of multiple or complex data structures may lower the usefulness of this strategy.
Effectiveness: Defense in Depth
代码示例 (2)
The following example demonstrates the weakness.
#include <stdio.h> #include <unistd.h> #define BUFSIZER1 512 #define BUFSIZER2 ((BUFSIZER1/2) - 8) int main(int argc, char **argv) { char *buf1R1; char *buf2R1; char *buf2R2; char *buf3R2; buf1R1 = (char *) malloc(BUFSIZER1); buf2R1 = (char *) malloc(BUFSIZER1); free(buf2R1); buf2R2 = (char *) malloc(BUFSIZER2); buf3R2 = (char *) malloc(BUFSIZER2); strncpy(buf2R1, argv[1], BUFSIZER1-1); free(buf1R1); free(buf2R2); free(buf3R2); }
Bad · C
The following code illustrates a use after free error:
char* ptr = (char*)malloc (SIZE); if (err) { abrt = 1; free(ptr); } ... if (abrt) { logError("operation aborted before commit", ptr); }
Bad · C
CVE ID标题CVSS风险等级Published
CVE-2026-19176 Chrome 151.0.7922.109前存在Skia内存使用后释放漏洞 — Chrome--2026-08-06
CVE-2026-19175 Chrome <151.0.7922.109 支付模块释放后使用漏洞 — Chrome--2026-08-06
CVE-2026-19171 Google Chrome <151.0.7922.109 释放后使用漏洞 — Chrome--2026-08-06
CVE-2026-19165 Chrome < 151.0.7922.109 扩展程序UAF漏洞 — Chrome--2026-08-06
CVE-2026-19166 Chrome<151.0.7922.109 Web Authentication Use-After-Free漏洞 — Chrome--2026-08-06
CVE-2026-19163 Chrome < 151.0.7922.109 媒体使用-after-free导致沙箱逃逸 — Chrome--2026-08-06
CVE-2026-19159 Chrome低于151.0.7922.109存在视图后使用免费漏洞 — Chrome--2026-08-06
CVE-2026-19158 Chrome <151.0.7922.109 视图界面使用后释放漏洞 — Chrome--2026-08-06
CVE-2026-19155 Chrome <151.0.7922.109 支付模块Use After Free漏洞 — Chrome--2026-08-06
CVE-2026-19151 Google Chrome 151.0.7922.109前 堆释放后使用漏洞 — Chrome--2026-08-06
CVE-2026-19147 Chrome<151.0.7922.109 Linux Aura释放后使用漏洞 — Chrome--2026-08-06
CVE-2026-19145 Chrome <151.0.7922.109 UAF漏洞致远程代码执行 — Chrome--2026-08-06
CVE-2026-19144 Chrome 151.0.7922.109 前版本 HTML 释放后使用漏洞 — Chrome--2026-08-06
CVE-2026-19141 Chrome Android 多个版本 Use-After-Free 漏洞 — Chrome--2026-08-06
CVE-2026-19142 Chrome <151.0.7922.109 视图Use After Free漏洞 — Chrome--2026-08-06
CVE-2026-19140 Chrome<151.0.7922.109 GPU使用释放后漏洞 — Chrome--2026-08-06
CVE-2026-19170 Android Chrome<151.0.7922.109 WebKit UAF致沙箱逃逸 — Chrome--2026-08-06
CVE-2026-19172 Chrome<151.0.7922.109 Views Use-After-Free导致沙盒逃逸 — Chrome--2026-08-06
CVE-2026-19154 Chrome < 151.0.7922.109 Skia Use After Free 沙箱逃逸 — Chrome--2026-08-06
CVE-2026-19149 Chrome Linux <151.0.7922.109 Aura Use After Free漏洞 — Chrome--2026-08-06
CVE-2026-19137 Chrome Android 低于 151.0.7922.109 WebGl 释放后使用漏洞 — Chrome--2026-08-06
CVE-2026-19108 MZ Automation libiec61850 释放后使用漏洞 — libiec61850 5.3 Medium2026-08-06
CVE-2026-1289 Autodesk Revit PDF文件解析UAF漏洞 — Revit 7.8 High2026-08-06
CVE-2026-43632 llama.cpp b7492-b9060 记号化处理接口 Use-After-Free 漏洞 — llama.cpp 8.1 High2026-08-06
CVE-2026-43631 llama.cpp b7492–b9060 llama-server 使用后可释放远程代码执行漏洞 — llama.cpp 8.1 High2026-08-06
CVE-2026-71226 Libkcapi 一次 AIO 路径错误内存损坏漏洞 — Red Hat Enterprise Linux 10 7.3 High2026-08-05
CVE-2026-18785 Open62541 缓冲区错误漏洞 — open62541 5.3 Medium2026-08-04
CVE-2026-56848 Node.js 资源管理错误漏洞 — node--2026-08-04
CVE-2026-11368 zephyrproject zephyr 资源管理错误漏洞 — zephyr 7.1 High2026-08-04
CVE-2026-62870 Microsoft 365 Apps for Enterprise 资源管理错误漏洞 — Microsoft 365 Apps for Enterprise 8.8 High2026-08-03

CWE-416(释放后使用) 是常见的弱点类别,本平台收录该类弱点关联的 3237 条 CVE 漏洞。