Use After Free (CWE-416)
CWE-416 is a memory safety weakness in which a product references memory after freeing it. The freed region may be reallocated to another pointer, so operations through the old pointer act on memory now owned by different code. Dangling pointer and UAF are listed alternate terms.
About CWE-416
Using freed memory can corrupt valid data, crash the process, or leak sensitive information. If attacker-controlled data fills the reallocated region, function pointers there may be overwritten and code execution becomes possible.
Mitigations
- +Choose a language with automatic memory management.
- +Set pointers to NULL once they are freed, as defense in depth that reduces the chance of code execution.
- +Use compiler-integrated runtime checks such as AddressSanitizer during testing to catch invalid memory use.
Detection
Fuzzing and automated static analysis are both rated highly effective. Runtime error checkers like AddressSanitizer add moderate coverage when paired with crafted inputs.
CWE-416 Vulnerabilities
26 CVEs| CVE | Title | Vendor | CVSS | EPSS | KEV | Published |
|---|---|---|---|---|---|---|
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Microsoft | 7.0 | 0.3% | KEV | 2026-08-11 |
| CVE-2025-62221 | Windows Cloud Files Mini Filter Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.5% | KEV | 2025-12-09 |
| CVE-2025-27038 | Use After Free in Graphics | Qualcomm, Inc. | 7.5 | 1.0% | KEV | 2025-06-03 |
| CVE-2025-32709 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Microsoft | 7.8 | 2.2% | KEV | 2025-05-13 |
| CVE-2025-30400 | Microsoft DWM Core Library Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.9% | KEV | 2025-05-13 |
| CVE-2025-32701 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.4% | KEV | 2025-05-13 |
| CVE-2025-29824 | Windows Common Log File System Driver Elevation of Privilege Vulnerability | Microsoft | 7.8 | 13.9% | KEV | 2025-04-08 |
| CVE-2025-24983 | Windows Win32 Kernel Subsystem Elevation of Privilege Vulnerability | Microsoft | 7.0 | 1.4% | KEV | 2025-03-11 |
| CVE-2025-21334 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.6% | KEV | 2025-01-14 |
| CVE-2025-21335 | Windows Hyper-V NT Kernel Integration VSP Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.4% | KEV | 2025-01-14 |
| CVE-2024-43047 | Use After Free in DSP Service | Qualcomm, Inc. | 7.8 | 0.7% | KEV | 2024-10-07 |
| CVE-2024-38193 | Windows Ancillary Function Driver for WinSock Elevation of Privilege Vulnerability | Microsoft | 7.8 | 28.7% | KEV | 2024-08-13 |
| CVE-2024-38107 | Windows Power Dependency Coordinator Elevation of Privilege Vulnerability | Microsoft | 7.8 | 1.6% | KEV | 2024-08-13 |
| CVE-2022-2586 | Linux Kernel Use-After-Free Vulnerability | The Linux Kernel Organization | 5.3 | 10.2% | KEV | 2024-01-08 |
| CVE-2024-4610 | Mali GPU Kernel Driver allows improper GPU memory processing operations | Arm Ltd | 7.4 | 0.8% | KEV | 2024-06-07 |
| CVE-2024-1086 | Use-after-free in Linux kernel's netfilter: nf_tables component | Linux | 7.8 | 28.1% | KEV | 2024-01-31 |
| CVE-2023-33063 | Use After Free in DSP Services | Qualcomm, Inc. | 7.8 | 0.7% | KEV | 2023-12-05 |
| CVE-2023-21608 | Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability | Adobe | 7.8 | 61.5% | KEV | 2023-01-18 |
| CVE-2023-4211 | Mali GPU Kernel Driver Allows Improper GPU Memory Processing Operations | Arm Ltd | 5.5 | 1.1% | KEV | 2023-10-01 |
| CVE-2023-36802 | Microsoft Streaming Service Proxy Elevation of Privilege Vulnerability | Microsoft | 7.8 | 27.9% | KEV | 2023-09-12 |
| CVE-2021-25394 | Samsung Mobile Devices Race Condition Vulnerability | Samsung Mobile | 6.4 | 0.4% | KEV | 2021-06-11 |
| CVE-2023-29336 | Win32k Elevation of Privilege Vulnerability | Microsoft | 7.8 | 41.2% | KEV | 2023-05-09 |
| CVE-2023-0266 | Use after free in SNDRV_CTL_IOCTL_ELEM in Linux Kernel | Linux | 7.9 | 3.7% | KEV | 2023-01-30 |
| CVE-2023-21674 | Windows Advanced Local Procedure Call (ALPC) Elevation of Privilege Vulnerability | Microsoft | 8.8 | 41.0% | KEV | 2023-01-10 |
| CVE-2021-28550 | Adobe Acrobat Reader use after free vulnerability could lead to arbitrary code execution | Adobe | 9.6 | 51.9% | KEV | 2021-09-02 |
| CVE-2026-33526 | Squid vulnerable to Denial of Service in ICP Request handling | squid-cache | 9.2 | 12.8% | 2026-03-26 |
Most Affected Vendors
Tool Categories That Address This Weakness
Frequently Asked Questions
What is a use after free (CWE-416)?→
It is a bug where a program keeps using a pointer to memory that has already been released, and that memory may now hold unrelated data.
Does setting a pointer to NULL after free fix CWE-416?→
MITRE classifies it as defense in depth. A later access may still crash, but the risk of code execution is reduced or removed.
How many exploited vulnerabilities are classified as CWE-416?→
This database lists 26 CVE records mapped to CWE-416 by their CVE Numbering Authority. 25 of them are in the CISA Known Exploited Vulnerabilities catalog, and CISA links 2 to known ransomware campaigns. Examples include CVE-2026-68820, CVE-2025-62221, CVE-2025-27038.
Weakness definitions summarized from the CWE List, © The MITRE Corporation, used under the CWE Terms of Use. CWE mappings come from each CVE record's CNA. Exploited-in-the-wild data from the CISA KEV catalog (CC0). This site is not endorsed or certified by MITRE or CISA.