CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,867 vulnerabilities with CWE-401
CVE-2025-37982 MEDIUM
Linux Kernel - Use-After-Free in wl1251_tx_work
CVSS 5.5
CVE-2025-37980 MEDIUM
Linux Kernel 3.13-6.6.87, 6.7.0-6.12.24, 6.13.0-6.14.3 - Use-After-Free in blk_register_queue Error Path
CVSS 5.5
CVE-2025-37962 MEDIUM
Linux Kernel 6.1.134-6.1.138, 6.6.87-6.6.90, 6.12.23-6.12.28, 6.14.2-6.14.6 - Use-After-Free in ksmbd
CVSS 5.5
CVE-2025-37955 MEDIUM
Linux Kernel 6.11-6.12.28, 6.13-6.14.6 - Use-After-Free in virtnet_xsk_pool_enable
CVSS 5.5
CVE-2025-37951 MEDIUM
Linux Kernel 4.18-6.1.139 6.2.0-6.6.91 6.7.0-6.12.29 6.13.0-6.14.7 - Use-After-Free in DRM V3D Job Timeout Handling
CVSS 5.5
CVE-2025-37941 MEDIUM
Linux Kernel - Use-After-Free in wcd937x_soc_codec_probe
CVSS 5.5
CVE-2025-37909 MEDIUM
Linux Kernel 4.17-6.14.5 - Use-After-Free in LAN743x GSO Descriptor Mapping
CVSS 5.5
CVE-2025-37905 MEDIUM
Linux Kernel 5.13-5.14.x, 5.16-6.1.137, 6.2-6.6.89, 6.7-6.12.27, 6.13-6.14.5 - Use-After-Free in SCMI Device Destruction
CVSS 5.5
CVE-2025-37904 MEDIUM
Linux Kernel 6.13-6.14.5 - Use-After-Free in btrfs_iget()
CVSS 5.5
CVE-2025-47935 HIGH
Multer < 2.0.0 - Denial of Service via Unclosed Stream Handling
CVSS 7.5
CVE-2025-23165 LOW
Node.js <v20,v22 - Memory Corruption
CVSS 3.7
CVE-2025-47279 LOW
Undici < 5.29.0, 6.0.0-6.21.1, 7.0.0-7.4.9 - Memory Leak via Repeated Webhook Calls
CVSS 3.1
CVE-2025-37874 MEDIUM
Linux Kernel 6.2-6.6.87, 6.7-6.12.24, 6.13-6.14.3 - Use-After-Free in ngbe_probe Error Path
CVSS 5.5
CVE-2025-37872 MEDIUM
Linux Kernel 6.8-6.12.25 6.13.0-6.14.4 - Use-After-Free in txgbe_probe Error Path
CVSS 5.5
CVE-2025-37807 MEDIUM
Linux Kernel - Use-After-Free in BPF Percpu Hashmap
CVSS 5.5
CVE-2025-22886 LOW
OpenHarmony < 5.0.3 - Denial of Service via Missing Memory Release
CVSS 3.3
CVE-2025-1992 MEDIUM
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.1 - Authenticated Denial of Service via Memory Leak
CVSS 5.3
CVE-2025-37788 MEDIUM
Linux Kernel - Use-After-Free in cxgb4_init_ethtool_filters()
CVSS 5.5
CVE-2025-37764 MEDIUM
Linux Kernel - Use-After-Free in DRM Imagination Firmware Memory Handling
CVSS 5.5
CVE-2025-37757 HIGH
Linux Kernel - Use-After-Free in TIPC Link Transmission
CVSS 7.5
CVE-2025-37744 MEDIUM
Linux Kernel 6.14-6.14.2 - Use-After-Free in ath12k_pci_remove()
CVSS 5.5
CVE-2025-37743 MEDIUM
Linux Kernel 6.3-6.14.3 - Use-After-Free in ath12k WiFi Driver Statistics Handling
CVSS 5.5
CVE-2025-23160 MEDIUM
Linux Kernel - Use-After-Free in Mediatek Vcodec SCP Device Handling
CVSS 5.5
CVE-2025-46420 MEDIUM
Red Hat Enterprise Linux 8 - Use-After-Free in libsoup Header Quality List Parser
CVSS 6.5
CVE-2025-39989 MEDIUM
Linux Kernel <5.17-5.10 LTS - Info Disclosure
CVSS 5.5
Details
Vulnerabilities 1,867
Exploit Likelihood Medium