CWE-401— Missing Release of Memory after Effective Lifetime (Memory Leak)
The product does not sufficiently track and release allocated memory after it has been used, making the memory unavailable for reallocation and reuse.— MITRE CWE catalog
1,963 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-401page 39 of 40
- CVE-2025-61146MEDIUMCVSS 4.0EG 4.02026-02-23
saitoha libsixel until v1.8.7 was discovered to contain a memory leak via the component malloc_stub.c.
- CVE-2022-23091MEDIUMCVSS 4.0EG 4.02024-02-15
A particular case of memory sharing is mishandled in the virtual memory system. This is very similar to SA-21:08.vm, but with a different root cause. An unprivileged local user process can maintain a mapping of a page after it is freed, …
- CVE-2019-19073MEDIUMCVSS 4.0EG 4.02019-11-18
Memory leaks in drivers/net/wireless/ath/ath9k/htc_hst.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering wait_for_completion_timeout() failures. This affects the htc_config…
- CVE-2026-91926LOWCVSS 3.7EG 3.72026-09-15
A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM target-info parser when a crafted NTLM CHALLENGE message contains duplicated string-valued AV_PAIR entries. The parser allocates memory for each string value but does not fr…
- CVE-2026-78131LOWCVSS 3.7EG 3.72026-09-11
strongSwan 4.2.0 through 6.0.7 has a missing release of memory after its effective lifetime in the x509 plugin's attribute certificate parser.
- CVE-2026-78127LOWCVSS 3.7EG 3.72026-09-11
libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.
- CVE-2026-78124LOWCVSS 3.7EG 3.72026-09-11
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
- CVE-2026-61871LOWCVSS 3.7EG 3.72026-07-15
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the ICON decoder that occurs when a memory allocation fails. Processing a crafted ICON file that triggers an allocation failure leaks memory, which may lead to a denial of…
- CVE-2026-61868LOWCVSS 3.7EG 3.72026-07-15
ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memory leak in the YUV decoder that occurs when opening of the blob fails. Repeated triggering can lead to resource exhaustion (denial of service).
- CVE-2026-22025LOWCVSS 3.7EG 3.72026-01-10
CryptoLib provides a software-only solution using the CCSDS Space Data Link Security Protocol - Extended Procedures (SDLS-EP) to secure communications between a spacecraft running the core Flight System (cFS) and a ground station. Prior to…
- CVE-2025-53019LOWCVSS 3.7EG 3.72025-07-14
ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 7.1.2-0 and 6.9.13-26, in ImageMagick's `magick stream` command, specifying multiple consecutive `%d` format specifiers in …
- CVE-2025-23165LOWCVSS 3.7EG 3.72025-05-19
In Node.js, the `ReadFileUtf8` internal binding leaks memory due to a corrupted pointer in `uv_fs_s.file`: a UTF-16 path buffer is allocated but subsequently overwritten when the file descriptor is set. This results in an unrecoverable mem…
- CVE-2023-34450LOWCVSS 3.7EG 3.72023-07-03
CometBFT is a Byzantine Fault Tolerant (BFT) middleware that takes a state transition machine and replicates it on many machines. An internal modification made in versions 0.34.28 and 0.37.1 to the way struct `PeerState` is serialized to J…
- CVE-2022-3633LOWCVSS 3.5EG 3.52022-10-21
A vulnerability classified as problematic has been found in Linux Kernel. Affected is the function j1939_session_destroy of the file net/can/j1939/transport.c. The manipulation leads to memory leak. It is recommended to apply a patch to fi…
- CVE-2022-3624LOWCVSS 3.5EG 3.52022-10-21
A vulnerability was found in Linux Kernel and classified as problematic. Affected by this issue is the function rlb_arp_xmit of the file drivers/net/bonding/bond_alb.c of the component IPsec. The manipulation leads to memory leak. It is re…
- CVE-2019-20382LOWCVSS 3.5EG 3.52020-03-05
QEMU 4.1.0 has a memory leak in zrle_compress_data in ui/vnc-enc-zrle.c during a VNC disconnect operation because libz is misused, resulting in a situation where memory allocated in deflateInit2 is not freed in deflateEnd.
- CVE-2026-66011LOWCVSS 3.3EG 3.32026-07-25
ImageMagick before 7.1.2-27 contains a memory leak vulnerability in the magick command-line interface when invalid options are provided. Attackers can trigger memory exhaustion by repeatedly supplying malformed command-line arguments to co…
- CVE-2026-56375LOWCVSS 3.3EG 3.32026-07-15
ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers can trigger failed actions to exhaust memory resources and cause denial of service.
- CVE-2025-60361LOWCVSS 3.3EG 3.32025-10-17
radare2 v5.9.8 and before contains a memory leak in the function bochs_open.
- CVE-2025-27562LOWCVSS 3.3EG 3.32025-08-11
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
- CVE-2025-24925LOWCVSS 3.3EG 3.32025-08-11
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
- CVE-2025-24844LOWCVSS 3.3EG 3.32025-08-11
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
- CVE-2025-8225LOWCVSS 3.3EG 3.32025-07-27
A vulnerability was found in GNU Binutils 2.44 and classified as problematic. This issue affects the function process_debug_info of the file binutils/dwarf.c of the component DWARF Section Handler. The manipulation leads to memory leak. At…
- CVE-2025-5324LOWCVSS 3.3EG 3.32025-05-29
A vulnerability, which was classified as problematic, was found in TechPowerUp GPU-Z 2.23.0. Affected is the function sub_140001880 in the library GPU-Z.sys of the component 0x8000645C IOCTL Handler. The manipulation leads to memory leak. …
- CVE-2025-22886LOWCVSS 3.3EG 3.32025-05-06
in OpenHarmony v5.0.3 and prior versions allow a local attacker case DOS through missing release of memory.
- CVE-2021-47671LOWCVSS 3.3EG 3.32025-04-17
In the Linux kernel, the following vulnerability has been resolved: can: etas_es58x: es58x_rx_err_msg(): fix memory leak in error path In es58x_rx_err_msg(), if can->do_set_mode() fails, the function directly returns without calling neti…
- CVE-2025-25057LOWCVSS 3.3EG 3.32025-04-07
in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.
- CVE-2025-3198LOWCVSS 3.3EG 3.32025-04-04
A vulnerability has been found in GNU Binutils 2.43/2.44 and classified as problematic. Affected by this vulnerability is the function display_info of the file binutils/bucomm.c of the component objdump. The manipulation leads to memory le…
- CVE-2025-20011LOWCVSS 3.3EG 3.32025-03-04
in OpenHarmony v5.0.2 and prior versions allow a local attacker case DOS through missing release of memory.
- CVE-2024-43696LOWCVSS 3.3EG 3.32024-10-08
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause DOS by memory leak.
- CVE-2024-38388LOWCVSS 3.3EG 3.32024-06-21
In the Linux kernel, the following vulnerability has been resolved: ALSA: hda/cs_dsp_ctl: Use private_free for control cleanup Use the control private_free callback to free the associated data block. This ensures that the memory won't le…
- CVE-2021-47089LOWCVSS 3.3EG 3.32024-03-04
In the Linux kernel, the following vulnerability has been resolved: kfence: fix memory leak when cat kfence objects Hulk robot reported a kmemleak problem: unreferenced object 0xffff93d1d8cc02e8 (size 248): comm "cat", pid 233…
- CVE-2023-5349LOWCVSS 3.3EG 3.32023-10-30
A memory leak flaw was found in ruby-magick, an interface between Ruby and ImageMagick. This issue can lead to a denial of service (DOS) by memory exhaustion.
- CVE-2023-2602LOWCVSS 3.3EG 3.32023-06-06
A vulnerability was found in the pthread_create() function in libcap. This issue may allow a malicious actor to use cause __real_pthread_create() to return an error, which can exhaust the process memory.
- CVE-2021-3574LOWCVSS 3.3EG 3.32022-08-26
A vulnerability was found in ImageMagick-7.0.11-5, where executing a crafted file with the convert command, ASAN detects memory leaks.
- CVE-2020-27755LOWCVSS 3.3EG 3.32020-12-08
in SetImageExtent() of /MagickCore/image.c, an incorrect image depth size can cause a memory leak because the code which checks for the proper image depth size does not reset the size in the event there is an invalid size. The patch resets…
- CVE-2020-3959LOWCVSS 3.3EG 3.32020-05-29
VMware ESXi (6.7 before ESXi670-202004101-SG and 6.5 before ESXi650-202005401-SG), VMware Workstation (15.x before 15.1.0) and VMware Fusion (11.x before 11.1.0) contain a memory leak vulnerability in the VMCI module. A malicious actor wit…
- CVE-2019-19057LOWCVSS 3.3EG 3.32019-11-18
Two memory leaks in the mwifiex_pcie_init_evt_ring() function in drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11 allow attackers to cause a denial of service (memory consumption) by triggering mwifiex_map_pci…
- CVE-2019-3815LOWCVSS 3.3EG 3.32019-01-28
A memory leak was discovered in the backport of fixes for CVE-2018-16864 in Red Hat Enterprise Linux. Function dispatch_message_real() in journald-server.c does not free the memory allocated by set_iovec_field_free() to store the `_CMDLINE…
- CVE-2022-3629LOWCVSS 2.6EG 3.32022-10-21
A vulnerability was found in Linux Kernel. It has been declared as problematic. This vulnerability affects the function vsock_connect of the file net/vmw_vsock/af_vsock.c. The manipulation leads to memory leak. The complexity of an attack …
- CVE-2025-9165LOWCVSS 2.5EG 3.32025-08-19
A flaw has been found in LibTIFF 4.7.0. This affects the function _TIFFmallocExt/_TIFFCheckRealloc/TIFFHashSetNew/InitCCITTFax3 of the file tools/tiffcmp.c of the component tiffcmp. Executing manipulation can lead to memory leak. The attac…
- CVE-2025-8277LOWCVSS 3.1EG 3.12025-09-09
A flaw was found in libssh's handling of key exchange (KEX) processes when a client repeatedly sends incorrect KEX guesses. The library fails to free memory during these rekey operations, which can gradually exhaust system memory. This iss…
- CVE-2025-47279LOWCVSS 3.1EG 3.12025-05-15
Undici is an HTTP/1.1 client for Node.js. Prior to versions 5.29.0, 6.21.2, and 7.5.0, applications that use undici to implement a webhook-like system are vulnerable. If the attacker set up a server with an invalid certificate, and they ca…
- CVE-2025-1152LOWCVSS 3.1EG 3.12025-02-10
A vulnerability classified as problematic has been found in GNU Binutils 2.43. Affected is the function xstrdup of the file xstrdup.c of the component ld. The manipulation leads to memory leak. It is possible to launch the attack remotely.…
- CVE-2025-1151LOWCVSS 3.1EG 3.12025-02-10
A vulnerability was found in GNU Binutils 2.43. It has been rated as problematic. This issue affects the function xmemdup of the file xmemdup.c of the component ld. The manipulation leads to memory leak. The attack may be initiated remotel…
- CVE-2025-1150LOWCVSS 3.1EG 3.12025-02-10
A vulnerability was found in GNU Binutils 2.43. It has been declared as problematic. This vulnerability affects the function bfd_malloc of the file libbfd.c of the component ld. The manipulation leads to memory leak. The attack can be init…
- CVE-2025-1149LOWCVSS 3.1EG 3.12025-02-10
A vulnerability was found in GNU Binutils 2.43. It has been classified as problematic. This affects the function xstrdup of the file libiberty/xmalloc.c of the component ld. The manipulation leads to memory leak. It is possible to initiate…
- CVE-2025-1148LOWCVSS 3.1EG 3.12025-02-10
A vulnerability was found in GNU Binutils 2.43 and classified as problematic. Affected by this issue is the function link_order_scan of the file ld/ldelfgen.c of the component ld. The manipulation leads to memory leak. The attack may be la…
- CVE-2026-61869LOWCVSS 2.9EG 2.92026-07-15
ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in the MIFF encoder that occurs when a memory allocation fails during MIFF image processing, which can lead to denial of service.
- CVE-2026-61867LOWCVSS 2.9EG 2.92026-07-15
ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the TIFF encoder when memory allocation fails. Attackers can trigger allocation failures during TIFF image processing to cause memory exhaustion and denial of service.
Map vulnerabilities like CWE-401 to your infrastructure
EchelonGraph correlates every CVE — across CWE-401 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →