CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 12 of 19
- CVE-2017-6074HIGHCVSS 7.8EG 7.82017-02-18
The dccp_rcv_state_process function in net/dccp/input.c in the Linux kernel through 4.9.11 mishandles DCCP_PKT_REQUEST packet data structures in the LISTEN state, which allows local users to obtain root privileges or cause a denial of serv…
- CVE-2016-8693HIGHCVSS 7.8EG 7.82017-02-15
Double free vulnerability in the mem_close function in jas_stream.c in JasPer before 1.900.10 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a crafted BMP image to the imginfo command.
- CVE-2016-9806HIGHCVSS 7.8EG 7.82016-12-28
Race condition in the netlink_dump function in net/netlink/af_netlink.c in the Linux kernel before 4.6.3 allows local users to cause a denial of service (double free) or possibly have unspecified other impact via a crafted application that…
- CVE-2016-5384HIGHCVSS 7.8EG 7.82016-08-13
fontconfig before 2.12.1 does not validate offsets, which allows local users to trigger arbitrary free calls and consequently conduct double free attacks and execute arbitrary code via a crafted cache file.
- CVE-2003-1048HIGHCVSS 7.8EG 7.82004-07-27
Double free vulnerability in mshtml.dll for certain versions of Internet Explorer 6.x allows remote attackers to cause a denial of service (application crash) via a malformed GIF image.
- CVE-2019-3896HIGHCVSS 7.0EG 7.82019-06-19
A double-free can happen in idr_remove_all() in lib/idr.c in the Linux kernel 2.6 branch. An unprivileged local attacker can use this flaw for a privilege escalation or for a system crash and a denial of service (DoS).
- CVE-2017-2636HIGHCVSS 7.0EG 7.82017-03-07
Race condition in drivers/tty/n_hdlc.c in the Linux kernel through 4.10.1 allows local users to gain privileges or cause a denial of service (double free) by setting the HDLC line discipline.
- CVE-2022-25717HIGHCVSS 6.7EG 7.82023-01-09
Memory corruption in display due to double free while allocating frame buffer memory
- CVE-2022-28389HIGHCVSS 5.5EG 7.82022-04-03
mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel through 5.17.1 has a double free.
- CVE-2022-28388HIGHCVSS 5.5EG 7.82022-04-03
usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel through 5.17.1 has a double free.
- CVE-2023-1449HIGHCVSS 5.3EG 7.82023-03-17
A vulnerability has been found in GPAC 2.3-DEV-rev35-gbbca86917-master and classified as problematic. This vulnerability affects the function gf_av1_reset_state of the file media_tools/av_parsers.c. The manipulation leads to double free. I…
- CVE-2023-26545HIGHCVSS 4.7EG 7.82023-02-25
In the Linux kernel before 6.1.13, there is a double free in net/mpls/af_mpls.c upon an allocation failure (for registering the sysctl table under a new location) during the renaming of a device.
- CVE-2026-46183HIGHEG 7.82026-05-28
In the Linux kernel, the following vulnerability has been resolved: mm/damon/sysfs-schemes: protect path kfree() with damon_sysfs_lock damon_sysfs_quot_goal->path can be read and written by users, via DAMON sysfs 'path' file. It can als…
- CVE-2026-46162HIGHEG 7.82026-05-28
In the Linux kernel, the following vulnerability has been resolved: ice: fix double free in ice_sf_eth_activate() error path When auxiliary_device_add() fails, ice_sf_eth_activate() jumps to aux_dev_uninit and calls auxiliary_device_unin…
- CVE-2026-31787HIGHEG 7.82026-04-30
In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting privcmd_vm_ops defines .close (privcmd_close), but neither .may_split nor .open. When userspace does a partial munmap() on…
- CVE-2026-31686HIGHEG 7.82026-04-27
In the Linux kernel, the following vulnerability has been resolved: mm/kasan: fix double free for kasan pXds kasan_free_pxd() assumes the page table is always struct page aligned. But that's not always the case for all architectures. E…
- CVE-2014-4343HIGHCVSS v2 7.6EG 7.62014-08-14
Double free vulnerability in the init_ctx_reselect function in the SPNEGO initiator in lib/gssapi/spnego/spnego_mech.c in MIT Kerberos 5 (aka krb5) 1.10.x through 1.12.x before 1.12.2 allows remote attackers to cause a denial of service (m…
- CVE-2026-33630HIGHCVSS 7.5EG 7.52026-09-03
c-ares is an asynchronous resolver library. From ver 1.32.3 until 1.34.7, a use-after-free / double-free in c-ares' query-completion handling. The same flaw — a query's callback being invoked while the query is still linked in the channe…
- CVE-2026-84964HIGHCVSS 7.5EG 7.52026-09-03
A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause the same…
- CVE-2026-52023HIGHCVSS 7.5EG 7.52026-09-01
An issue in kamailio v.6.1.1 and before allows a remote attacker to cause a denial of service via the ims_registrar_pcscf module, specifically the pcscf_save_pending/save_pending path and security-agreement parsing in sec_agree.c:parse_sec…
- CVE-2026-75159HIGHCVSS 7.5EG 7.52026-08-27
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling cond…
- CVE-2026-18798HIGHCVSS 7.5EG 7.52026-08-25
Issue summary: QUIC server may double free QRX (QUIC record layer RX) object when channel creation fails for initial packet. Impact summary: Double free leads to heap corruption, which typically results in termination of QUIC server proc…
- CVE-2026-47895HIGHCVSS 7.5EG 7.52026-08-22
In strongSwan before 6.0.7, identity parsing/cloning is mishandled. Parsed EAP-Identities that result in an empty but non-NULL encoding are not correctly cloned and trigger a double-free once the duplicates are destroyed.
- CVE-2026-20338HIGHCVSS 7.5EG 7.52026-08-07
A vulnerability in the zip archive parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper memory handling when processing content in zip fil…
- CVE-2026-66373HIGHCVSS 7.5EG 7.52026-07-25
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting b…
- CVE-2026-43823HIGHCVSS 7.5EG 7.52026-07-23
When initializing an RSA public key from DER or PEM bytes throws an error, the EVP_PKEY* is double-freed: first in the catch block, then in the deinit. This can lead to a crash on future memory allocations. This double-free manifests when …
- CVE-2026-50685HIGHCVSS 7.5EG 7.52026-07-14
Double free in Windows DHCP Server allows an authorized attacker to execute code over a network.
- CVE-2026-14164HIGHCVSS 7.5EG 7.52026-06-30
A double free issue has been identified in libarchive's RAR5 reader. During parsing of a specially crafted RAR5 archive, the filtered_buf pointer may remain stale after being freed during unpacking state reinitialization. Subsequent proces…
- CVE-2026-11576HIGHCVSS 7.5EG 7.52026-06-19
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally calls fx_file_close() even when the file …
- CVE-2026-33811HIGHCVSS 7.5EG 7.52026-05-07
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
- CVE-2026-4358HIGHCVSS 7.5EG 7.52026-03-17
A specially crafted aggregation query with $lookup by an authenticated user with write privileges can cause a double-free or use-after-free memory issue in the slot-based execution (SBE) engine when an in-memory hash table is spilled to di…
- CVE-2025-69650HIGHCVSS 7.5EG 7.52026-03-06
GNU Binutils thru 2.46 readelf contains a double free vulnerability when processing a crafted ELF binary with malformed relocation data. During GOT relocation handling, dump_relocations may return early without initializing the all_relocat…
- CVE-2026-25556HIGHCVSS 7.5EG 7.52026-02-06
MuPDF versions 1.23.0 through 1.27.0 contain a double-free vulnerability in fz_fill_pixmap_from_display_list() when an exception occurs during display list rendering. The function accepts a caller-owned fz_pixmap pointer but incorrectly dr…
- CVE-2026-21918HIGHCVSS 7.5EG 7.52026-01-15
A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX and MX Series allows an unauthenticated, network-based attacker to cause a Denial-of-Service (DoS). On all SRX and MX Series platforms, w…
- CVE-2025-61990HIGHCVSS 7.5EG 7.52025-10-15
When using a multi-bladed platform with more than one blade, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluate…
- CVE-2025-53948HIGHCVSS 7.5EG 7.52025-08-18
The Sante PACS Server allows a remote attacker to crash the main thread by sending a crafted HL7 message, causing a denial-of-service condition. The application would require a manual restart and no authentication is required.
- CVE-2025-50169HIGHCVSS 7.5EG 7.52025-08-12
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an unauthorized attacker to execute code over a network.
- CVE-2025-23322HIGHCVSS 7.5EG 7.52025-08-06
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability where multiple requests could cause a double free when a stream is cancelled before it is processed. A successful exploit of this vulnerability might lead to den…
- CVE-2025-5262HIGHCVSS 7.5EG 7.52025-05-27
A double-free could have occurred in `vpx_codec_enc_init_multi` after a failed allocation when initializing the encoder for WebRTC. This could have caused memory corruption and a potentially exploitable crash. This vulnerability affects Th…
- CVE-2024-39564HIGHCVSS 7.5EG 7.52025-02-05
This is a similar, but different vulnerability than the issue reported as CVE-2024-39549. A double-free vulnerability in the routing process daemon (rpd) of Juniper Networks Junos OS and Junos OS Evolved allows an attacker to send a ma…
- CVE-2024-12107HIGHCVSS 7.5EG 7.52024-12-04
Double-Free Vulnerability in uD3TN BPv7 Caused by Malformed Endpoint Identifier allows remote attacker to reliably cause DoS
- CVE-2024-2002HIGHCVSS 7.5EG 7.52024-03-18
A double-free vulnerability was found in libdwarf. In a multiply-corrupted DWARF object, libdwarf may try to dealloc(free) an allocation twice, potentially causing unpredictable and various results.
- CVE-2024-21606HIGHCVSS 7.5EG 7.52024-01-12
A Double Free vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series allows a network-based, unauthenticated attacker to cause a Denial of Service (DoS). In a remote access VPN scenario, if a "tcp-…
- CVE-2023-42459HIGHCVSS 7.5EG 7.52023-10-16
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). In affected versions specific DATA submessages can be sent to a discovery locator which may trigger a free error. This c…
- CVE-2023-38434HIGHCVSS 7.5EG 7.52023-07-18
xHTTP 72f812d has a double free in close_connection in xhttp.c via a malformed HTTP request method.
- CVE-2023-3312HIGHCVSS 7.5EG 7.52023-06-19
A vulnerability was found in drivers/cpufreq/qcom-cpufreq-hw.c in cpufreq subsystem in the Linux Kernel. This flaw, during device unbind will lead to double release problem leading to denial of service.
- CVE-2022-4450HIGHCVSS 7.5EG 7.52023-02-08
The function PEM_read_bio_ex() reads a PEM file from a BIO and parses and decodes the "name" (e.g. "CERTIFICATE"), any header data and the payload data. If the function succeeds then the "name_out", "header" and "data" arguments are popula…
- CVE-2022-47975HIGHCVSS 7.5EG 7.52023-01-06
The DUBAI module has a double free vulnerability. Successful exploitation of this vulnerability may affect system availability.
- CVE-2019-5797HIGHCVSS 7.5EG 7.52022-09-29
Double free in DOMStorage in Google Chrome prior to 73.0.3683.75 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.
- CVE-2022-2509HIGHCVSS 7.5EG 7.52022-08-01
A vulnerability found in gnutls. This security flaw happens because of a double free error occurs during verification of pkcs7 signatures in gnutls_pkcs7_verify function.
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →