目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1359 元

100%

CWE-666 在生命周期错误阶段对资源进行操作 类漏洞列表 3

CWE-666 在生命周期错误阶段对资源进行操作 类弱点 3 条 CVE 漏洞汇总,含 AI 中文分析。

MITRE CWE 官方描述
The product performs an operation on a resource at the wrong phase of the resource's lifecycle, which can lead to unexpected behaviors. A resource's lifecycle includes several phases: initialization, use, and release. For each phase, it is important to follow the specifications outlined for how to operate on the resource and to ensure that the resource is in the expected phase. Otherwise, if a resource is in one phase but the operation is not valid for that phase (i.e., an incorrect phase of the resource's lifetime), then this can produce resultant weaknesses. For example, using a resource before it has been fully initialized could cause corruption or incorrect data to be used.
常见影响 (1)
Other Other
缓解措施 (1)
Architecture and Design Follow the resource's lifecycle from creation to release.
代码示例 (1)
The following code shows a simple example of a double free vulnerability.
char* ptr = (char*)malloc (SIZE); ... if (abrt) { free(ptr); } ... free(ptr);
Bad · C
CVE ID 标题 CVSS 风险等级 Published
CVE-2026-16148 it82xx2驱动致内核恐慌 — zephyr 4.6 Medium 2026-09-14
CVE-2026-15460 Zephyr 蓝牙经典L2CAP接收路径状态验证缺失漏洞 — zephyr 5.4 Medium 2026-09-09
CVE-2026-68930 Eugene Russh 处理逻辑错误漏洞 — russh 6.5 Medium 2026-08-03

CWE-666(在生命周期错误阶段对资源进行操作) 是常见的弱点类别,本平台收录该类弱点关联的 3 条 CVE 漏洞。