The product calls free() twice on the same memory address.
823 vulnerabilities with CWE-415
CVE-2026-43460
HIGH
spi: rockchip-sfc: Fix double-free in remove() callback
CVSS 7.8
CVE-2026-43414
CRITICAL
scsi: qla2xxx: Completely fix fcport double free
CVSS 9.8
CVE-2026-43328
HIGH
cpufreq: governor: fix double free in cpufreq_dbs_governor_init() error path
CVSS 7.8
CVE-2026-33811
HIGH
Crash when handling long CNAME response in net
CVSS 7.5
CVE-2026-43278
HIGH
dm: clear cloned request bio pointer when last clone bio completes
CVSS 7.8
CVE-2026-43276
HIGH
net: mana: Fix double destroy_workqueue on service rescan PCI path
CVSS 7.8
CVE-2026-43260
HIGH
bnxt_en: Fix RSS context delete logic
CVSS 7.8
CVE-2026-43249
HIGH
9p/xen: protect xen_9pfs_front_free against concurrent calls
CVSS 8.8
CVE-2026-43196
HIGH
soc: ti: pruss: Fix double free in pruss_clk_mux_setup()
CVSS 7.8
CVE-2026-43178
HIGH
procfs: fix possible double mmput() in do_procmap_query()
CVSS 7.8
CVE-2026-43128
HIGH
RDMA/umem: Fix double dma_buf_unpin in failure path
CVSS 7.8
CVE-2026-43120
HIGH
RDMA/irdma: Fix double free related to rereg_user_mr
CVSS 7.8
CVE-2026-43097
HIGH
PCI: hv: Fix double ida_free in hv_pci_probe error path
CVSS 7.8
CVE-2026-23918
HIGH
Apache HTTP Server: http2: double free and possible RCE on early reset
CVSS 8.8
CVE-2026-43011
CRITICAL
net/x25: Fix potential double free of skb
CVSS 9.8
CVE-2026-43007
HIGH
accel/qaic: Handle DBC deactivation if the owner went away
CVSS 7.8
CVE-2026-31759
HIGH
usb: ulpi: fix double free in ulpi_register_interface() error path
CVSS 7.8
CVE-2026-31745
HIGH
reset: gpio: fix double free in reset_add_gpio_aux_device() error path
CVSS 7.8
CVE-2026-31730
HIGH
misc: fastrpc: possible double-free of cctx->remote_heap
CVSS 7.8
CVE-2026-31787
HIGH
xen/privcmd: fix double free via VMA splitting
CVSS 7.8
CVE-2026-5657
MEDIUM
Double Free in Wireshark
CVSS 5.5
CVE-2026-31686
HIGH
mm/kasan: fix double free for kasan pXds
CVSS 7.8
CVE-2026-31609
CRITICAL
smb: client: avoid double-free in smbd_free_send_io() after smbd_send_batch_flush()
CVSS 9.8
CVE-2026-31608
CRITICAL
smb: server: avoid double-free in smb_direct_free_sendmsg after smb_direct_flush_send_list()
CVSS 9.8
CVE-2026-31507
HIGH
net/smc: fix double-free of smc_spd_priv when tee() duplicates splice pipe buffer
CVSS 7.8
Details
Vulnerabilities
823
Exploit Likelihood
High