CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,744 vulnerabilities with CWE-401
CVE-2025-38409 MEDIUM
Linux Kernel 3.12-6.1.144, 6.2-6.6.97, 6.7-6.12.37, 6.13-6.15.6 - Use-After-Free in DRM MSM Submit Error Path
CVSS 5.5
CVE-2025-38405 MEDIUM
Linux Kernel 6.10.10-6.12.37, 6.11.0-6.12.37, 6.13.0-6.15.6 - Use-After-Free in NVMe Target Bio Integrity Handling
CVSS 5.5
CVE-2025-38390 MEDIUM
Linux Kernel 6.7-6.12.37, 6.13-6.15.6 - Use-After-Free in ARM FFA Notifier Callback
CVSS 5.5
CVE-2025-38384 MEDIUM
Linux Kernel - Use-After-Free in MTD SPI-NAND ECC Engine Configuration
CVSS 5.5
CVE-2025-53537 HIGH
LibHTP < 0.5.51 - Memory Leak via LZMA Decompression
CVSS 7.5
CVE-2025-46686 LOW
Redis < 8.0.3 - Authenticated Denial of Service via Multi-Bulk Command Memory Allocation
CVSS 3.5
CVE-2025-53019 LOW
ImageMagick < 6.9.13-26 - Out-of-bounds Read via Filename Template Format Specifiers
CVSS 3.7
CVE-2025-52986 MEDIUM
Juniper Junos OS and Junos OS Evolved - Use-After-Free in RPD via RIB Sharding Show Commands
CVSS 5.5
CVE-2025-53020 HIGH
Apache HTTP Server 2.4.17-2.4.63 - Use-After-Free
CVSS 7.5
CVE-2025-38345 MEDIUM
Linux Kernel < 5.4.295 - Use-After-Free in ACPI Operand Cache Handling
CVSS 5.5
CVE-2025-38344 MEDIUM
Linux Kernel < 5.4.295, 5.5.0-6.15.4 - Use-After-Free in ACPI Cache Handling
CVSS 5.5
CVE-2025-38300 MEDIUM
Linux Kernel 5.5-6.1.141, 6.2-6.6.93, 6.7-6.12.33, 6.13-6.15.2 - Use-After-Free in sun8i-ce-cipher DMA Handling
CVSS 5.5
CVE-2025-38258 MEDIUM
Linux Kernel 6.3-6.6.95, 6.7-6.12.35, 6.13-6.15.4 - Use-After-Free in DAMON memcg_path_store
CVSS 5.5
CVE-2025-7068 LOW
HDF5 1.14.6 - Memory Leak in H5FL__malloc
CVSS 3.3
CVE-2025-38228 MEDIUM
Linux Kernel - Use-After-Free in e5010_probe()
CVSS 5.5
CVE-2025-38199 MEDIUM
Linux Kernel 6.3-6.15.4 - Use-After-Free in ath12k WiFi Station RX Stats Allocation
CVSS 5.5
CVE-2025-38185 MEDIUM
Linux Kernel - Use-After-Free in atmtcp_c_send()
CVSS 5.5
CVE-2025-38165 MEDIUM
Linux Kernel - Use-After-Free in skb_linearize via sk_psock_backlog
CVSS 5.5
CVE-2025-38148 MEDIUM
Linux Kernel - Use-After-Free in One-Step Timestamping
CVSS 5.5
CVE-2025-38124 MEDIUM
Linux Kernel - Memory Corruption in UDP GSO skb_segment
CVSS 5.5
CVE-2025-38115 MEDIUM
Linux Kernel Use-After-Free in SFQ Qdisc (4.16-6.15.3)
CVSS 5.5
CVE-2025-6498 LOW
HTACG tidy-html5 5.8.0 - Memory Leak in defaultAlloc Function
CVSS 3.3
CVE-2025-38057 MEDIUM
Linux Kernel 5.6-6.12.30 - Use-After-Free in ESP-in-TCP Error Paths
CVSS 5.5
CVE-2025-38015 MEDIUM
Linux Kernel 6.0.9-6.14.7 Use-After-Free in idxd_alloc Error Handling
CVSS 5.5
CVE-2025-38011 MEDIUM
Linux Kernel 6.6-6.12.30 - Use-After-Free in AMDGPU CSA Unmap
CVSS 5.5
Details
Vulnerabilities 1,744
Exploit Likelihood Medium