Skip to main content

About CWE-416

Using freed memory can corrupt valid data, crash the process, or leak sensitive information. If attacker-controlled data fills the reallocated region, function pointers there may be overwritten and code execution becomes possible.

MITRE name
Use After Free
Abstraction
Variant: linked to a certain type of product, typically a specific language or technology
Status
Stable
Also known as
Dangling pointer, UAF, Use-After-Free

Mitigations

  • +Choose a language with automatic memory management.
  • +Set pointers to NULL once they are freed, as defense in depth that reduces the chance of code execution.
  • +Use compiler-integrated runtime checks such as AddressSanitizer during testing to catch invalid memory use.

Detection
Fuzzing and automated static analysis are both rated highly effective. Runtime error checkers like AddressSanitizer add moderate coverage when paired with crafted inputs.

CWE-416 Vulnerabilities

26 CVEs
CVETitleVendorCVSSEPSSKEVPublished
CVE-2026-68820
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Microsoft7.00.3%KEV2026-08-11
CVE-2025-62221
Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability
Microsoft7.82.5%KEV2025-12-09
CVE-2025-27038
Use After Free in Graphics
Qualcomm, Inc.7.51.0%KEV2025-06-03
CVE-2025-32709
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Microsoft7.82.2%KEV2025-05-13
CVE-2025-30400
Microsoft DWM Core Library Elevation of Privilege Vulnerability
Microsoft7.81.9%KEV2025-05-13
CVE-2025-32701
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Microsoft7.81.4%KEV2025-05-13
CVE-2025-29824
Windows Common Log File System Driver Elevation of Privilege Vulnerability
Microsoft7.813.9%KEV2025-04-08
CVE-2025-24983
Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability
Microsoft7.01.4%KEV2025-03-11
CVE-2025-21334
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
Microsoft7.81.6%KEV2025-01-14
CVE-2025-21335
Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability
Microsoft7.81.4%KEV2025-01-14
CVE-2024-43047
Use After Free in DSP Service
Qualcomm, Inc.7.80.7%KEV2024-10-07
CVE-2024-38193
Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability
Microsoft7.828.7%KEV2024-08-13
CVE-2024-38107
Windows Power Dependency Coordinator Elevation of Privilege Vulnerability
Microsoft7.81.6%KEV2024-08-13
CVE-2022-2586
Linux Kernel Use-After-Free Vulnerability
The Linux Kernel Organization5.310.2%KEV2024-01-08
CVE-2024-4610
Mali GPU Kernel Driver allows improper GPU memory processing operations
Arm Ltd7.40.8%KEV2024-06-07
CVE-2024-1086
Use-after-free in Linux kernel's netfilter: nf_tables component
Linux7.828.1%KEV2024-01-31
CVE-2023-33063
Use After Free in DSP Services
Qualcomm, Inc.7.80.7%KEV2023-12-05
CVE-2023-21608
Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability
Adobe7.861.5%KEV2023-01-18
CVE-2023-4211
Mali GPU Kernel Driver Allows Improper GPU Memory Processing Operations
Arm Ltd5.51.1%KEV2023-10-01
CVE-2023-36802
Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability
Microsoft7.827.9%KEV2023-09-12
CVE-2021-25394
Samsung Mobile Devices Race Condition Vulnerability
Samsung Mobile6.40.4%KEV2021-06-11
CVE-2023-29336
Win32k Elevation of Privilege Vulnerability
Microsoft7.841.2%KEV2023-05-09
CVE-2023-0266
Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel
Linux7.93.7%KEV2023-01-30
CVE-2023-21674
Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability
Microsoft8.841.0%KEV2023-01-10
CVE-2021-28550
Adobe Acrobat Reader use after free vulnerability could lead to arbitrary code execution
Adobe9.651.9%KEV2021-09-02
CVE-2026-33526
Squid vulnerable to Denial of Service in ICP Request handling
squid-cache9.212.8%2026-03-26

Frequently Asked Questions

What is a use after free (CWE-416)?→

It is a bug where a program keeps using a pointer to memory that has already been released, and that memory may now hold unrelated data.

Does setting a pointer to NULL after free fix CWE-416?→

MITRE classifies it as defense in depth. A later access may still crash, but the risk of code execution is reduced or removed.

How many exploited vulnerabilities are classified as CWE-416?→

This database lists 26 CVE records mapped to CWE-416 by their CVE Numbering Authority. 25 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 2 to known ransomware campaigns. Examples include CVE-2026-68820, CVE-2025-62221, CVE-2025-27038.

Sources

Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.