CWE-416: Use After Free

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

2,308
Total CVEs
181
Critical
1,972
High
8.0
Avg CVSS
10
In CISA KEV

Yearly Trend

2026
104
2025
719
2024
659
2023
248
2022
207

Top Affected Vendors

1 Linux 767
2 Google 387
3 Microsoft 259
4 Debian 227
5 Fedoraproject 194
6 Adobe 131
7 Foxit 84
8 Qualcomm 83
9 Apple 75
10 Mozilla 53

All Use After Free CVEs (2,308)

CVE-2022-49535
7.8

A use-after-free vulnerability in the Linux kernel's lpfc SCSI driver allows local attackers to cause a kernel panic or potentially execute arbitrary ...

Feb 26, 2025
CVE-2022-49524
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's cx23885 media driver. When the driver fails to set DMA mask during device init...

Feb 26, 2025
CVE-2022-49501
7.8

This CVE involves a use-after-free vulnerability in the Linux kernel's USB network driver (usbnet) that occurs during USB Ethernet adapter disconnecti...

Feb 26, 2025
CVE-2022-49505
7.8

This is a use-after-free vulnerability in the Linux kernel's NFC subsystem where the rfkill pointer is not properly nulled out after unregistration, a...

Feb 26, 2025
CVE-2022-49493
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's rt5645 audio codec driver. The improper cleanup order during device removal co...

Feb 26, 2025
CVE-2022-49479
7.8

This is a use-after-free vulnerability in the Linux kernel's mt76 wireless driver that occurs during station removal. It allows attackers with local a...

Feb 26, 2025
CVE-2022-49470
7.8

A use-after-free vulnerability in the Linux kernel's Bluetooth MediaTek SDIO driver allows attackers to potentially execute arbitrary code or cause sy...

Feb 26, 2025
CVE-2022-49474
7.8

A race condition in the Linux kernel's Bluetooth subsystem allows use-after-free when connecting the same socket twice consecutively. This can lead to...

Feb 26, 2025
CVE-2022-49464
7.8

This is a use-after-free vulnerability in the Linux kernel's EROFS filesystem implementation, specifically in the ztailpacking feature. It allows atta...

Feb 26, 2025
CVE-2022-49465
7.8

A use-after-free vulnerability in the Linux kernel's block I/O throttling subsystem (blk-throttle) allows local attackers to potentially crash the sys...

Feb 26, 2025
CVE-2022-49426
7.8

This is a use-after-free vulnerability in the Linux kernel's ARM SMMU v3 SVA (Shared Virtual Addressing) subsystem. It allows attackers with local acc...

Feb 26, 2025
CVE-2022-49416
7.8

This is a use-after-free vulnerability in the Linux kernel's WiFi subsystem (mac80211) that occurs during channel context operations. When exploited, ...

Feb 26, 2025
CVE-2022-49419
7.8

A use-after-free vulnerability in the Linux kernel's vesafb video framebuffer driver allows local attackers to potentially crash the system or execute...

Feb 26, 2025
CVE-2022-49411
7.8

A use-after-free vulnerability in the Linux kernel's BFQ I/O scheduler allows attackers to cause kernel crashes or potentially execute arbitrary code ...

Feb 26, 2025
CVE-2022-49412
7.8

A use-after-free vulnerability in the Linux kernel's BFQ I/O scheduler allows local attackers to cause kernel memory corruption, potentially leading t...

Feb 26, 2025
CVE-2022-49413
7.8

A use-after-free vulnerability in the Linux kernel's BFQ I/O scheduler allows an attacker to cause kernel memory corruption when processes migrate bet...

Feb 26, 2025
CVE-2022-49385
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's driver subsystem. When driver attachment fails, the system improperly frees me...

Feb 26, 2025
CVE-2022-49388
7.8

This is a use-after-free vulnerability in the Linux kernel's UBI (Unsorted Block Images) subsystem that occurs when volume creation fails. It allows a...

Feb 26, 2025
CVE-2022-49390
7.8

This is a use-after-free vulnerability in the Linux kernel's MACsec implementation where a network device (real_dev) can be freed while still being re...

Feb 26, 2025
CVE-2022-49377
7.8

This is a use-after-free vulnerability in the Linux kernel's block multi-queue (blk-mq) subsystem. It allows attackers with local access to potentiall...

Feb 26, 2025
CVE-2022-49359
7.8

This is a use-after-free vulnerability in the Linux kernel's Panfrost GPU driver that allows local attackers to potentially crash the system or execut...

Feb 26, 2025
CVE-2022-49362
7.8

This is a use-after-free vulnerability in the Linux kernel's NFSD (Network File System Daemon) that could allow an attacker to crash the kernel or pot...

Feb 26, 2025
CVE-2022-49349
7.8

This is a use-after-free vulnerability in the Linux kernel's ext4 filesystem driver that occurs during directory rename operations. Attackers with loc...

Feb 26, 2025
CVE-2022-49328
7.8

This is a use-after-free vulnerability in the Linux kernel's mt76 wireless driver that allows an attacker to potentially execute arbitrary code or cau...

Feb 26, 2025
CVE-2022-49287
7.8

This is a use-after-free vulnerability in the Linux kernel's TPM (Trusted Platform Module) subsystem. It allows local attackers to potentially crash t...

Feb 26, 2025
CVE-2022-49288
7.8

A race condition vulnerability in the Linux kernel's ALSA PCM subsystem allows concurrent writes to proc files controlling buffer preallocation, poten...

Feb 26, 2025
CVE-2022-49291
7.8

This CVE describes a race condition vulnerability in the Linux kernel's ALSA PCM subsystem where concurrent hw_params and hw_free ioctl calls can lead...

Feb 26, 2025
CVE-2022-49275
7.8

This is a use-after-free vulnerability in the Linux kernel's CAN (Controller Area Network) subsystem affecting m_can drivers. It allows attackers with...

Feb 26, 2025
CVE-2022-49270
7.8

This is a use-after-free vulnerability in the Linux kernel's device mapper (dm) subsystem that occurs during cleanup of zoned block devices. An attack...

Feb 26, 2025
CVE-2022-49258
7.8

A use-after-free vulnerability in the Linux kernel's ccree cryptographic driver allows attackers to potentially execute arbitrary code or cause system...

Feb 26, 2025
CVE-2022-49236
7.8

This is a use-after-free vulnerability in the Linux kernel's BPF subsystem that occurs due to a race condition during module loading. It allows local ...

Feb 26, 2025
CVE-2022-49238
7.8

This is a use-after-free vulnerability in the Linux kernel's ath11k Wi-Fi driver for Qualcomm QCA6390 and WCN6855 chipsets. When a station disconnects...

Feb 26, 2025
CVE-2022-49223
7.8

This is a use-after-free vulnerability in the Linux kernel's CXL (Compute Express Link) subsystem where a decoder object can reference a freed parent ...

Feb 26, 2025
CVE-2022-49196
7.8

This is a use-after-free vulnerability in the Linux kernel's powerpc/pseries subsystem that allows local attackers to cause a kernel crash (denial of ...

Feb 26, 2025
CVE-2022-49179
7.8

CVE-2022-49179 is a use-after-free vulnerability in the Linux kernel's BFQ I/O scheduler that can lead to kernel memory corruption. When exploited, it...

Feb 26, 2025
CVE-2022-49182
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's HNS3 network driver. Attackers could potentially crash the kernel or execute a...

Feb 26, 2025
CVE-2022-49176
7.8

This is a use-after-free vulnerability in the Linux kernel's BFQ I/O scheduler that can lead to kernel memory corruption. Attackers with local access ...

Feb 26, 2025
CVE-2022-49168
7.8

This CVE-2022-49168 is a use-after-free vulnerability in the Linux kernel's Btrfs filesystem driver. When a repair bio submission fails, improper clea...

Feb 26, 2025
CVE-2022-49127
7.8

This CVE addresses a use-after-free vulnerability in the Linux kernel's ref_tracker component, which tracks reference counts for kernel objects. The v...

Feb 26, 2025
CVE-2022-49136
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's Bluetooth subsystem. When the HCI_UNREGISTER flag is set during device unregis...

Feb 26, 2025
CVE-2022-49111
7.8

This is a use-after-free vulnerability in the Linux kernel's Bluetooth subsystem that allows an attacker to cause memory corruption and potentially ex...

Feb 26, 2025
CVE-2022-49114
7.8

This is a use-after-free vulnerability in the Linux kernel's Fibre Channel SCSI subsystem. An attacker could potentially cause a kernel crash or execu...

Feb 26, 2025
CVE-2022-49087
7.8

A race condition in the Linux kernel's rxrpc subsystem allows a use-after-free vulnerability during network namespace cleanup. This can lead to kernel...

Feb 26, 2025
CVE-2022-49093
7.8

A use-after-free vulnerability in the Linux kernel's skbuff coalescing mechanism when using page_pool fragment recycling. This allows memory corruptio...

Feb 26, 2025
CVE-2022-49082
7.8

This is a use-after-free vulnerability in the Linux kernel's mpt3sas SCSI driver. When removing an expander node, the driver frees memory but then att...

Feb 26, 2025
CVE-2022-49085
7.8

This is a use-after-free vulnerability in the Linux kernel's DRBD (Distributed Replicated Block Device) subsystem. It allows attackers with local acce...

Feb 26, 2025
CVE-2022-49078
7.8

A use-after-free vulnerability in the Linux kernel's LZ4 decompression function (LZ4_decompress_safe_partial) allows reading out of bounds when proces...

Feb 26, 2025
CVE-2022-49076
7.8

This is a use-after-free vulnerability in the Linux kernel's RDMA hfi1 driver that occurs when cleaning up memory management structures. It allows loc...

Feb 26, 2025
CVE-2022-49059
7.8

This is a use-after-free vulnerability in the Linux kernel's NFC (Near Field Communication) subsystem that can lead to kernel crashes or potential cod...

Feb 26, 2025
CVE-2022-49053
7.8

This CVE describes a use-after-free vulnerability in the Linux kernel's SCSI target subsystem (tcmu). Attackers with local access could potentially ex...

Feb 26, 2025

About Use After Free (CWE-416)

Referencing memory after it has been freed can cause a program to crash, use unexpected values, or execute code.

Our database tracks 2,308 CVEs classified as CWE-416, with 181 rated critical and 1,972 rated high severity. The average CVSS score for Use After Free vulnerabilities is 8.0.

External reference: View CWE-416 on MITRE CWE →

Monitor Use After Free Vulnerabilities

Get alerted when new Use After Free CVEs affect your infrastructure.

Start Monitoring Free