CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,867 vulnerabilities with CWE-401
CVE-2026-40336 LOW
libgphoto2 has memory leak in ptp_unpack_Sony_DPD() secondary enumeration list in ptp-pack.c
CVSS 2.4
CVE-2026-33782 MEDIUM
Junos OS: MX Series: In specific DHCPv6 scenarios jdhcpd memory increases continuously with subscriber logouts
CVSS 6.5
CVE-2026-33780 MEDIUM
Junos OS and Junos OS Evolved: In an EVPN-MPLS scenario churn of ESI routes causes a memory leak in l2ald
CVSS 6.5
CVE-2026-33775 MEDIUM
Junos OS: MX Series: Mismatch between configured and received packet types causes memory leak in bbe-smgd
CVSS 6.5
CVE-2026-34052 MEDIUM
LTI JupyterHub Authenticator: Unbounded Memory Growth via Nonce Storage (Denial of Service)
CVSS 5.9
CVE-2026-31400 MEDIUM
sunrpc: fix cache_request leak in cache_release
CVSS 5.5
CVE-2026-31390 MEDIUM
Linux Kernel drm/xe - xe_vm_madvise_ioctl Memory Leak
CVSS 5.5
CVE-2026-23464 MEDIUM
soc: microchip: mpfs: Fix memory leak in mpfs_sys_controller_probe()
CVSS 5.5
CVE-2026-23453 HIGH
net: ti: icssg-prueth: Fix memory leak in XDP_DROP for non-zero-copy mode
CVSS 7.5
CVE-2026-23444 HIGH
wifi: mac80211: always free skb on ieee80211_tx_prepare_skb() failure
CVSS 7.8
CVE-2026-23431 MEDIUM
spi: amlogic-spisg: Fix memory leak in aml_spisg_probe()
CVSS 5.5
CVE-2026-23430 MEDIUM
drm/vmwgfx: Don't overwrite KMS surface dirty tracker
CVSS 5.5
CVE-2026-23423 MEDIUM
btrfs: free pages on error in btrfs_uring_read_extent()
CVSS 5.5
CVE-2026-23418 MEDIUM
Linux Kernel drm/xe reg_sr - xa_store Failure Memory Leak
CVSS 5.5
CVE-2026-23414 HIGH
tls: Purge async_hold in tls_decrypt_async_wait()
CVSS 7.5
CVE-2026-23403 MEDIUM
apparmor: fix memory leak in verify_header
CVSS 5.5
CVE-2026-21714 MEDIUM
Node.js 20.20.1 22.22.1 24.14.0 25.8.1 - Memory Leak via HTTP/2 WINDOW_UPDATE Frames
CVSS 5.3
CVE-2026-23399 MEDIUM
nf_tables: nft_dynset: fix possible stateful expression memleak in error path
CVSS 5.5
CVE-2026-3650 HIGH
Grassroots DICOM Missing release of memory after effective lifetime
CVSS 7.5
CVE-2026-4247 HIGH
TCP: remotely exploitable DoS vector (mbuf leak)
CVSS 7.5
CVE-2026-20012 HIGH
Cisco IOS - Unauthenticated Denial of Service via IKEv2 Packet Parsing
CVSS 8.6
CVE-2026-3104 HIGH
Memory leak in code preparing DNSSEC proofs of non-existence
CVSS 7.5
CVE-2026-23389 MEDIUM
Linux kernel - Memory Leak in ice_set_ringparam()
CVSS 5.5
CVE-2026-23384 MEDIUM
RDMA/ionic: Fix kernel stack leak in ionic_create_cq()
CVSS 5.5
CVE-2026-23360 MEDIUM
nvme: fix admin queue leak on controller reset
CVSS 5.5
Details
Vulnerabilities 1,867
Exploit Likelihood Medium