The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
7,471 vulnerabilities with CWE-416
CVE-2026-6785
HIGH
Memory safety bugs fixed in Firefox ESR 115.35, Firefox ESR 140.10, Thunderbird ESR 140.10, Firefox 150 and Thunderbird 150
CVSS 7.5
CVE-2026-31669
CRITICAL
mptcp: fix slab-use-after-free in __inet_lookup_established
CVSS 9.8
CVE-2026-31665
HIGH
netfilter: nft_ct: fix use-after-free in timeout object destroy
CVSS 7.8
CVE-2026-31652
HIGH
mm/damon/stat: deallocate damon_call() failure leaking damon_ctx
CVSS 7.8
CVE-2026-31650
HIGH
mmc: vub300: fix use-after-free on disconnect
CVSS 7.8
CVE-2026-31644
HIGH
net: lan966x: fix use-after-free and leak in lan966x_fdma_reload()
CVSS 7.8
CVE-2026-31597
HIGH
ocfs2: fix use-after-free in ocfs2_fault() when VM_FAULT_RETRY
CVSS 7.8
CVE-2026-31589
CRITICAL
mm: call ->free_folio() directly in folio_unmap_invalidate()
CVSS 9.8
CVE-2026-31588
HIGH
KVM: x86: Use scratch field in MMIO fragment to hold small write values
CVSS 8.8
CVE-2026-31587
HIGH
ASoC: qcom: q6apm: move component registration to unmanaged version
CVSS 7.8
CVE-2026-31586
HIGH
mm: blk-cgroup: fix use-after-free in cgwb_release_workfn()
CVSS 7.8
CVE-2026-31584
HIGH
media: mediatek: vcodec: fix use-after-free in encoder release path
CVSS 7.8
CVE-2026-31583
HIGH
media: em28xx: fix use-after-free in em28xx_v4l2_open()
CVSS 7.8
CVE-2026-31582
HIGH
hwmon: (powerz) Fix use-after-free on USB disconnect
CVSS 7.8
CVE-2026-31581
HIGH
ALSA: 6fire: fix use-after-free on disconnect
CVSS 7.8
CVE-2026-31580
HIGH
bcache: fix cached_dev.sb_bio use-after-free and crash
CVSS 7.8
CVE-2026-31578
HIGH
media: as102: fix to not free memory after the device is registered in as102_usb_probe()
CVSS 7.8
CVE-2026-31576
HIGH
media: hackrf: fix to not free memory after the device is registered in hackrf_probe()
CVSS 7.8
CVE-2026-31566
HIGH
drm/amdgpu: Fix fence put before wait in amdgpu_amdkfd_submit_ib
CVSS 7.8
CVE-2026-31554
HIGH
futex: Require sys_futex_requeue() to have identical flags
CVSS 7.8
CVE-2026-31541
HIGH
tracing: Fix trace_marker copy link list updates
CVSS 7.8
CVE-2026-6919
CRITICAL
Google Chrome < 147.0.7727.117 - Use-After-Free in DevTools
CVSS 9.6
CVE-2026-31533
CRITICAL
Linux - Use-After-Free in TLS Encryption Error Path
CVSS 9.8
CVE-2026-31532
HIGH
Linux - Use-After-Free in raw_rcv() via ro->uniq
CVSS 7.8
CVE-2026-31530
HIGH
cxl/port: Fix use after free of parent_port in cxl_detach_ep()
CVSS 7.8
Details
Vulnerabilities
7,471
Exploit Likelihood
High