CWE-825

Expired Pointer Dereference

Parent: CWE-119 - Improper Restriction of Operations within the Bounds of a Memory Buffer

The product dereferences a pointer that contains a location for memory that was previously valid, but is no longer valid.

86 vulnerabilities with CWE-825
CVE-2026-17523 HIGH
Kernel: can:bcm: arbitrary kernel code execution leading to escalate privileges
CVSS 7.8
CVE-2026-10671 HIGH
User thread can re-initialize an in-use `k_pipe`, corrupting kernel wait queues (`CONFIG_USERSPACE`)
CVSS 7.1
CVE-2026-54778 MEDIUM
CoreWCF: UnixDomainSocket Non-Reentrant POSIX Identity Resolution
CVSS 6.2
CVE-2026-58592 HIGH
Ladybird - Web-Reachable Code Execution via Dangling FunctionType Reference in WebAssembly ESM Integration
CVSS 8.3
CVE-2026-12610 MEDIUM
Sssd: use-after-free crash in sssd' 'sssd_pam' process
CVSS 6.4
CVE-2026-57435 HIGH
Nokogiri: Possible Use-After-Free when setting an attribute value via `Nokogiri::XML::Attr#value=` or `#content=`
CVSS 7.5
CVE-2026-53085 HIGH
bpf: fix mm lifecycle in open-coded task_vma iterator
CVSS 7.8
CVE-2026-53033 HIGH
bpf, sockmap: Take state lock for af_unix iter
CVSS 7.8
CVE-2026-53006 CRITICAL
ipv6: fix possible UAF in icmpv6_rcv()
CVSS 9.8
CVE-2026-52976 HIGH
drm/xe: Fix error cleanup in xe_exec_queue_create_ioctl()
CVSS 7.8
CVE-2026-52973 HIGH
futex: Drop CLONE_THREAD requirement for private default hash alloc
CVSS 7.8
CVE-2026-52952 HIGH
iommu: Fix WARN_ON in __iommu_group_set_domain_nofail() due to reset
CVSS 8.8
CVE-2026-52950 HIGH
Linux Kernel DRM Xe DMA-BUF - Use-After-Free
CVSS 7.8
CVE-2026-52924 CRITICAL
sctp: purge outqueue on stale COOKIE-ECHO handling
CVSS 9.8
CVE-2026-52923 HIGH
ipc: limit next_id allocation to the valid ID range
CVSS 7.8
CVE-2026-12328 HIGH
Memory safety bugs fixed in Firefox ESR 115.37, Firefox ESR 140.12, Thunderbird ESR 140.12, Firefox 152 and Thunderbird 152
CVSS 8.1
CVE-2026-12326 HIGH
Memory safety bugs fixed in Firefox 152 and Thunderbird 152
CVSS 8.1
CVE-2026-12293 CRITICAL
Use-after-free in the Graphics: WebGPU component
CVSS 9.8
CVE-2026-12291 HIGH
Use-after-free in the Networking: HTTP component
CVSS 8.8
CVE-2026-42014 MEDIUM
Gnutls: fix use-after-free in gnutls_pkcs11_token_set_pin
CVSS 6.6
CVE-2026-6040 HIGH
Heap use-after-free in ODF number-format blank-width parsing
CVSS 7.3
CVE-2026-46523 MEDIUM
ImageMagick: Use-After-Free in MSL decoder.
CVSS 6.2
CVE-2026-45447 HIGH
Heap Use-After-Free in the PKCS7_verify() Function
CVSS 8.8
CVE-2026-46243 HIGH
smb: client: reject userspace cifs.spnego descriptions
CVSS 7.1
CVE-2026-44422 HIGH
FreeRDP RDPEAR NDR ref-id aliasing causes client-side UAF/double-free and type confusion
CVSS 7.5
Details
Vulnerabilities 86