CWE-401

Medium likelihood

Missing Release of Memory after Effective Lifetime

Parent: CWE-772 - Missing Release of Resource after Effective Lifetime

The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.

1,744 vulnerabilities with CWE-401
CVE-2026-23080 MEDIUM
Linux Kernel 4.12.0-6.18.7 - Use-After-Free in mcba_usb_read_bulk_callback
CVSS 5.5
CVE-2026-23079 MEDIUM
Linux Kernel - Use-After-Free in GPIO Character Device Lineinfo Notification
CVSS 5.5
CVE-2026-23075 MEDIUM
Linux Kernel - Use-After-Free in esd_usb_read_bulk_callback
CVSS 5.5
CVE-2026-23072 MEDIUM
Linux Kernel 6.10-6.12.67, 6.13-6.18.7, 6.19+ - Use-After-Free in L2TP Session Handling
CVSS 5.5
CVE-2026-23065 MEDIUM
Linux Kernel 6.8-6.12.68, 6.13-6.18.8 - Use-After-Free in wbrf_record()
CVSS 5.5
CVE-2026-23061 MEDIUM
Linux Kernel - Use-After-Free in kvaser_usb_read_bulk_callback
CVSS 5.5
CVE-2026-1757 MEDIUM
Red Hat Enterprise Linux - Denial of Service via xmllint Interactive Shell Memory Leak
CVSS 6.2
CVE-2026-23026 MEDIUM
Linux Kernel 5.11.0-6.18.6 Use-After-Free in gpi_peripheral_config
CVSS 5.5
CVE-2026-23024 MEDIUM
Linux Kernel 6.17-6.18.5 - Use-After-Free in idpf Flow Steering List
CVSS 5.5
CVE-2026-23023 MEDIUM
Linux Kernel - Use-After-Free in idpf_vport_rel()
CVSS 5.5
CVE-2026-23022 MEDIUM
Linux Kernel - Use-After-Free in idpf_vc_core_deinit
CVSS 5.5
CVE-2026-23021 MEDIUM
Linux Kernel - Use-After-Free in pegasus USB Network Driver
CVSS 5.5
CVE-2026-24828 HIGH
Is-Daouda is-Engine <3.3.4 - Use After Free
CVSS 7.5
CVE-2026-24825 MEDIUM
ydb-platform ydb < 24.4.4.2 - Use-After-Free in yajl yail_tree.C
CVE-2026-22979 MEDIUM
Linux Kernel < 6.1.161, 6.2.0-6.6.121, 6.7.0-6.12.66, 6.9.0-6.18.6, 5.15.154-5.16 - Use-After-Free in skb_segment_list
CVSS 5.5
CVE-2026-21909 MEDIUM
Juniper Junos OS and Junos OS Evolved - Unauthenticated Denial of Service via IS-IS Update Packet Memory Leak
CVSS 6.5
CVE-2026-22025 LOW
CryptoLib < 1.4.3 - Use-After-Free in KMC Server Error Handling
CVSS 3.7
CVE-2026-22024 MEDIUM
CryptoLib < 1.4.3 - Memory Leak in cryptography_encrypt()
CVSS 5.3
CVE-2026-21674 LOW
iccdev < 2.3.1.1 - Memory Leak in XML MPE Parsing Path
CVSS 3.3
CVE-2025-71290 MEDIUM
misc: ti_fpc202: fix a potential memory leak in probe function
CVSS 5.5
CVE-2025-71288 MEDIUM
memory: mtk-smi: fix device leaks on common probe
CVSS 5.5
CVE-2025-71287 MEDIUM
memory: mtk-smi: fix device leak on larb probe
CVSS 5.5
CVE-2025-71273 MEDIUM
wifi: rtw88: Use devm_kmemdup() in rtw_set_supported_band()
CVSS 5.5
CVE-2025-71272 MEDIUM
most: core: fix resource leak in most_register_interface error paths
CVSS 5.5
CVE-2025-71268 MEDIUM
btrfs: fix reservation leak in some error paths when inserting inline extent
CVSS 5.5
Details
Vulnerabilities 1,744
Exploit Likelihood Medium