← Back
CWE-416

8,657 CVEs • Abstraction: Variant • Likelihood of Exploit: High

Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.

JSON object

Loading...

CVEs (8,657)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Google
1Chrome
Jun 17, 2026
Aug 6, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Use after free in Dawn in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
1Google
1Chrome
Jun 17, 2026
Aug 6, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Use after free in Loader in Google Chrome prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
1Google
1Chrome
Jun 17, 2026
Aug 6, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Use after free in Downloads in Google Chrome on iOS prior to 127.0.6533.72 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
1Mozilla
1Firefox
Jun 17, 2026
Aug 6, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Incorrect garbage collection interaction could have led to a use-after-free. This vulnerability affects Firefox < 129.
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Aug 6, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Incorrect garbage collection interaction in IndexedDB could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
1Mozilla
3Firefox
Firefox EsrThunderbird
Jun 17, 2026
Aug 6, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Unexpected marking work at the start of sweeping could have led to a use-after-free. This vulnerability affects Firefox < 129, Firefox ESR < 115.14, Firefox ESR < 128.1, Thunderbird < 128.1, and Thunderbird < 115.14.
1Qualcomm
102Fastconnect 6200 Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+99 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption can occur if VBOs hold outdated or invalid GPU SMMU mappings, especially when the binding and reclaiming of memory buffers are performed at the same time.
1Qualcomm
136Ar8035 Firmware
Csra6620 FirmwareCsra6640 Firmware+133 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption as fence object may still be accessed in timeline destruct after isync fence is released.
1Qualcomm
151Ar8035 Firmware
Csra6620 FirmwareCsra6640 Firmware+148 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while creating a fence to wait on timeline events, and simultaneously signal timeline events.
1Qualcomm
246Ar8035 Firmware
Ar9380 FirmwareCsr8811 Firmware+243 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
Transient DOS while parsing fragments of MBSSID IE from beacon frame.
1Qualcomm
102Fastconnect 6200 Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+99 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
Memory corruption when the mapped pages in VBO are still mapped after reclaiming by shrinker.
1Qualcomm
71Fastconnect 6200 Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+68 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption when kernel driver attempts to trigger hardware fences.
1Qualcomm
102Fastconnect 6200 Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+99 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption while processing graphics kernel driver request to create DMA fence.
1Qualcomm
72Fastconnect 6200 Firmware
Fastconnect 6700 FirmwareFastconnect 6900 Firmware+69 more
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Memory corruption when memory mapped in a VBO is not unmapped by the GPU SMMU.
1Arm
35th Gen Gpu Architecture Kernel Driver
Bifrost Gpu Kernel DriverValhall Gpu Kernel Driver
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory proc...Show more
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p0; Valhall GPU Kernel Driver: from r41p0 through r49p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p0.Show less
1Arm
35th Gen Gpu Architecture Kernel Driver
Bifrost Gpu Kernel DriverValhall Gpu Kernel Driver
Jun 17, 2026
Aug 5, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory proc...Show more
Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm Ltd Valhall GPU Kernel Driver, Arm Ltd Arm 5th Gen GPU Architecture Kernel Driver allows a local non-privileged user to make improper GPU memory processing operations to gain access to already freed memory.This issue affects Bifrost GPU Kernel Driver: from r41p0 through r49p0; Valhall GPU Kernel Driver: from r41p0 through r49p0; Arm 5th Gen GPU Architecture Kernel Driver: from r41p0 through r49p0.Show less
3Neovim
NetappVim
3Hci Compute Node
NeovimVim
Sep 17, 2026
Aug 1, 2024
N/A· v4
4.2 MEDIUM· v3
N/A· v2
Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer...Show more
Vim is an open source command line text editor. double-free in dialog_changed() in Vim < v9.1.0648. When abandoning a buffer, Vim may ask the user what to do with the modified buffer. If the user wants the changed buffer to be saved, Vim may create a new Untitled file, if the buffer did not have a name yet. However, when setting the buffer name to Unnamed, Vim will falsely free a pointer twice, leading to a double-free and possibly later to a heap-use-after-free, which can lead to a crash. The issue has been fixed as of Vim patch v9.1.0648.Show less
1Linux
1Linux Kernel
Aug 4, 2026
Jul 30, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In the Linux kernel, the following vulnerability has been resolved: net: txgbe: free isb resources at the right time When using MSI/INTx interrupt, the shared interrupts are still being handled in the device remove rou...Show more
In the Linux kernel, the following vulnerability has been resolved: net: txgbe: free isb resources at the right time When using MSI/INTx interrupt, the shared interrupts are still being handled in the device remove routine, before free IRQs. So isb memory is still read after it is freed. Thus move wx_free_isb_resources() from txgbe_close() to txgbe_remove(). And fix the improper isb free action in txgbe_open() error handling path.Show less
1Linux
1Linux Kernel
Aug 4, 2026
Jul 30, 2024
N/A· v4
5.5 MEDIUM· v3
N/A· v2
In the Linux kernel, the following vulnerability has been resolved: net: rswitch: Avoid use-after-free in rswitch_poll() The use-after-free is actually in rswitch_tx_free(), which is inlined in rswitch_poll(). Since `s...Show more
In the Linux kernel, the following vulnerability has been resolved: net: rswitch: Avoid use-after-free in rswitch_poll() The use-after-free is actually in rswitch_tx_free(), which is inlined in rswitch_poll(). Since `skb` and `gq->skbs[gq->dirty]` are in fact the same pointer, the skb is first freed using dev_kfree_skb_any(), then the value in skb->len is used to update the interface statistics. Let's move around the instructions to use skb->len before the skb is freed. This bug is trivial to reproduce using KFENCE. It will trigger a splat every few packets. A simple ARP request or ICMP echo request is enough.Show less
1Linux
1Linux Kernel
Aug 4, 2026
Jul 30, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix inode number range checks Patch series "nilfs2: fix potential issues related to reserved inodes". This series fixes one use-after-free is...Show more
In the Linux kernel, the following vulnerability has been resolved: nilfs2: fix inode number range checks Patch series "nilfs2: fix potential issues related to reserved inodes". This series fixes one use-after-free issue reported by syzbot, caused by nilfs2's internal inode being exposed in the namespace on a corrupted filesystem, and a couple of flaws that cause problems if the starting number of non-reserved inodes written in the on-disk super block is intentionally (or corruptly) changed from its default value. This patch (of 3): In the current implementation of nilfs2, "nilfs->ns_first_ino", which gives the first non-reserved inode number, is read from the superblock, but its lower limit is not checked. As a result, if a number that overlaps with the inode number range of reserved inodes such as the root directory or metadata files is set in the super block parameter, the inode number test macros (NILFS_MDT_INODE and NILFS_VALID_INODE) will not function properly. In addition, these test macros use left bit-shift calculations using with the inode number as the shift count via the BIT macro, but the result of a shift calculation that exceeds the bit width of an integer is undefined in the C specification, so if "ns_first_ino" is set to a large value other than the default value NILFS_USER_INO (=11), the macros may potentially malfunction depending on the environment. Fix these issues by checking the lower bound of "nilfs->ns_first_ino" and by preventing bit shifts equal to or greater than the NILFS_USER_INO constant in the inode number test macros. Also, change the type of "ns_first_ino" from signed integer to unsigned integer to avoid the need for type casting in comparisons such as the lower bound check introduced this time.Show less