CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,753 vulnerabilities with CWE-401
CVE-2024-43861 MEDIUM
Linux Kernel 4.12-6.10.5 - Use-After-Free in qmi_wwan Non-IP Packet Handling
CVSS 5.5
CVE-2024-43854 MEDIUM
Linux Kernel - Memory Leak via Uninitialized Integrity Buffer
CVSS 5.5
CVE-2024-42263 MEDIUM
Linux Kernel 6.8-6.10.3 - Use-After-Free in DRM V3D Timestamp Extension
CVSS 5.5
CVE-2024-42262 MEDIUM
Linux Kernel 6.8-6.10.3 - Use-After-Free in DRM V3D Performance Extension
CVSS 5.5
CVE-2024-42477 MEDIUM
ggerganov llama.cpp < b3561 - Out-of-bounds Read via Unsafe rpc_tensor Type Member
CVSS 5.3
CVE-2024-42152 MEDIUM
Linux Kernel - Use-After-Free in NVMe Target Subsystem
CVSS 4.7
CVE-2024-42070 MEDIUM
Linux Kernel < 3.13 - Use-After-Free in nf_tables Register Store Validation
CVSS 5.5
CVE-2024-41078 MEDIUM
Linux Kernel - Use-After-Free in Btrfs Quota Root Handling
CVSS 5.5
CVE-2024-41076 MEDIUM
Linux Kernel - Use-After-Free in NFSv4 Security Label Handling
CVSS 5.5
CVE-2024-41066 MEDIUM
Linux Kernel < 6.1.101 - Use-After-Free in ibmvnic Driver
CVSS 5.5
CVE-2024-41025 MEDIUM
Linux Kernel 6.2-6.6.40 - Use-After-Free in fastrpc Audio Daemon Attach Operation
CVSS 5.5
CVE-2024-41023 MEDIUM
Linux Kernel 4.19.257-4.19.258 - Use-After-Free in Scheduler Deadline Task Reference Handling
CVSS 5.5
CVE-2024-41021 MEDIUM
Linux Kernel 6.6-6.6.43, 6.7-6.9.11, 6.10-6.10.1 - Use-After-Free in s390 Memory Management
CVSS 5.5
CVE-2024-41172 HIGH
Apache CXF 3.6.0-3.6.3 and 4.0.0-4.0.4 - Memory Leak in HTTP Client Conduit
CVSS 7.5
CVE-2024-41006 MEDIUM
Linux Kernel - Use-After-Free in nr_heartbeat_expiry
CVSS 5.5
CVE-2024-41002 MEDIUM
Linux Kernel - Use-After-Free in SEC Resource Release
CVSS 5.5
CVE-2024-41001 MEDIUM
Linux Kernel < 6.1.96, 5.1.0-6.1.96, 6.2.0-6.6.36, 6.7.0-6.9.7 - Use-After-Free in io_uring/sqpoll
CVSS 5.5
CVE-2024-40997 MEDIUM
Linux Kernel - Use-After-Free in AMD P-State CPU EPP Exit
CVSS 5.5
CVE-2024-40979 MEDIUM
Linux Kernel 6.3 through 6.9.7 - Memory Management Error in ath12k QMI
CVSS 5.5
CVE-2024-40942 MEDIUM
Linux Kernel - Use-After-Free in Mesh Path Resolution
CVSS 5.5
CVE-2024-40936 MEDIUM
Linux Kernel 6.3-6.6.34, 6.7-6.9.5, 6.10 - Use-After-Free in cxl/region
CVSS 5.5
CVE-2024-40934 MEDIUM
Linux Kernel - Use-After-Free in HID Logitech DJ Receiver
CVSS 5.5
CVE-2024-40932 MEDIUM
Linux Kernel < 4.19.317, 4.20.0-6.9.6 - Use-After-Free in DRM Exynos VIDI
CVSS 5.5
CVE-2024-39550 MEDIUM
Juniper Junos OS on MX Series with SPC3 - Unauthenticated Denial of Service via rtlogd Memory Leak
CVSS 6.5
CVE-2024-39549 HIGH
Juniper Junos OS and Junos OS Evolved - Denial of Service via BGP Path Attribute Update
CVSS 7.5
Details
Vulnerabilities 1,753
Exploit Likelihood Medium