CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 5 of 19
- CVE-2020-27153HIGHCVSS 8.6EG 8.62020-10-15
In BlueZ before 5.55, a double free was found in the gatttool disconnect_cb() routine from shared/att.c. A remote attacker could potentially cause a denial of service or code execution, during service discovery, due to a redundant disconne…
- CVE-2026-95702HIGHCVSS 8.5EG 8.52026-10-09
Use-after-free vulnerability in VFS in Google gVisor prior to release 20260831.0 on all platforms allows a local attacker with standard container privileges to achieve code execution in the host sentry process by double-freeing the backing…
- CVE-2026-64118HIGHCVSS 8.4EG 8.42026-07-19
In the Linux kernel, the following vulnerability has been resolved: qed: fix double free in qed_cxt_tables_alloc() If one of the later PF or VF CID bitmap allocations fails, qed_cid_map_alloc() jumps to cid_map_fail and frees the previou…
- CVE-2024-47404HIGHCVSS 8.4EG 8.42024-11-05
in OpenHarmony v4.1.0 and prior versions allow a local attacker cause the common permission is upgraded to root and sensitive information leak through double free.
- CVE-2024-21461HIGHCVSS 8.4EG 8.42024-07-01
Memory corruption while performing finish HMAC operation when context is freed by keymaster.
- CVE-2022-40522HIGHCVSS 8.4EG 8.42023-06-06
Memory corruption in Linux Networking due to double free while handling a hyp-assign.
- CVE-2022-40507HIGHCVSS 8.4EG 8.42023-06-06
Memory corruption due to double free in Core while mapping HLOS address to the list.
- CVE-2022-33307HIGHCVSS 8.4EG 8.42023-06-06
Memory Corruption due to double free in automotive when a bad HLOS address for one of the lists to be mapped is passed.
- CVE-2021-1934HIGHCVSS 8.4EG 8.42021-09-09
Possible memory corruption due to improper check when application loader object is explicitly destructed while application is unloading in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon In…
- CVE-2021-1888HIGHCVSS 8.4EG 8.42021-07-13
Memory corruption in key parsing and import function due to double freeing the same heap allocation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdr…
- CVE-2020-11246HIGHCVSS 8.4EG 8.42021-04-07
A double free condition can occur when the device moves to suspend mode during secure playback in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile
- CVE-2023-28296HIGHCVSS 7.8EG 8.42023-04-11
Visual Studio Remote Code Execution Vulnerability
- CVE-2019-3829HIGHCVSS 5.3EG 8.32019-03-27
A vulnerability was found in gnutls versions from 3.5.8 before 3.6.7. A memory corruption (double free) vulnerability in the certificate verification API. Any client or server application that verifies X.509 certificates with GnuTLS 3.5.8 …
- CVE-2026-85921HIGHCVSS 8.2EG 8.22026-09-14
Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
- CVE-2026-72958HIGHCVSS 8.2EG 8.22026-09-08
Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.
- CVE-2025-32988HIGHCVSS 8.2EG 8.22025-07-10
A flaw was found in GnuTLS. A double-free vulnerability exists in GnuTLS due to incorrect ownership handling in the export logic of Subject Alternative Name (SAN) entries containing an otherName. If the type-id OID is invalid or malformed,…
- CVE-2024-3446HIGHCVSS 8.2EG 8.22024-04-09
A double free vulnerability was found in QEMU virtio devices (virtio-gpu, virtio-serial-bus, virtio-crypto), where the mem_reentrancy_guard flag insufficiently protects against DMA reentrancy issues. This issue could allow a malicious priv…
- CVE-2020-11900HIGHCVSS 8.2EG 8.22020-06-17
The Treck TCP/IP stack before 6.0.1.41 has an IPv4 tunneling Double Free.
- CVE-2026-55007HIGHCVSS 8.1EG 8.12026-09-08
Double free in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
- CVE-2026-62889HIGHCVSS 8.1EG 8.12026-08-11
Double free in Windows Secure Socket Tunneling Protocol (SSTP) allows an unauthorized attacker to execute code over a network.
- CVE-2026-10653HIGHCVSS 8.1EG 8.12026-06-30
The Zephyr net_buf library (lib/net_buf/buf.c) manipulated both of its reference counts -- the per-header buf->ref and the per-data-block ref_count at the start of each variable/heap data allocation -- with plain non-atomic C operators (bu…
- CVE-2024-43447HIGHCVSS 8.1EG 8.12024-11-12
Windows SMBv3 Server Remote Code Execution Vulnerability
- CVE-2023-24903HIGHCVSS 8.1EG 8.12023-05-09
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2020-16970HIGHCVSS 8.1EG 8.12020-11-11
Azure Sphere Unsigned Code Execution Vulnerability
- CVE-2018-21086HIGHCVSS 8.1EG 8.12020-04-08
An issue was discovered on Samsung mobile devices with L(5.x), M(6.0), and N(7.x) software. There is a race condition with a resultant double free in vnswap_init_backing_storage. The Samsung ID is SVE-2017-11177 (February 2018).
- CVE-2017-10914HIGHCVSS 8.1EG 8.12017-07-05
The grant-table feature in Xen through 4.8.x has a race condition leading to a double free, which allows guest OS users to cause a denial of service (memory consumption), or possibly obtain sensitive information or gain privileges, aka XSA…
- CVE-2016-8360HIGHCVSS 8.1EG 8.12017-02-13
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. A specially crafted URL request sent to the SoftCMS ASP Webserver can cause a double free condition on the server allowing an attacker to modify memory locations and po…
- CVE-2026-69876HIGHCVSS 8.0EG 8.02026-09-08
Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
- CVE-2026-69322HIGHCVSS 8.0EG 8.02026-09-08
Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
- CVE-2025-5100HIGHCVSS 8.0EG 8.02025-05-23
A double-free condition occurs during the cleanup of temporary image files, which can be exploited to achieve memory corruption and potentially arbitrary code execution.
- CVE-2023-25801HIGHCVSS 8.0EG 8.02023-03-25
TensorFlow is an open source machine learning platform. Prior to versions 2.12.0 and 2.11.1, `nn_ops.fractional_avg_pool_v2` and `nn_ops.fractional_max_pool_v2` require the first and fourth elements of their parameter `pooling_ratio` to be…
- CVE-2026-47558HIGHCVSS 7.8EG 7.82026-09-30
NVIDIA GPU Display Driver for Linux contains a vulnerability in the kernel mode layer where an unprivileged user could cause a double-free of imported memory state. A successful exploit of this vulnerability might lead to code execution, d…
- CVE-2026-6794HIGHCVSS 7.8EG 7.82026-09-23
IBM Concert 1.0.0 through 3.0.0 has a double free vulnerability that exists due to incorrect memory management. A local attacker can exploit this flaw to corrupt heap memory and execute arbitrary code in the context of the affected process.
- CVE-2026-23789HIGHCVSS 7.8EG 7.82026-09-14
An issue was discovered in MFC in Samsung Mobile Processor and Wearable Processor Exynos 850, 1080, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, 2600, 1680, W920, W930, and W1000. A double-free vulnerability in the Exynos MFC enco…
- CVE-2026-79907HIGHCVSS 7.8EG 7.82026-09-08
Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- CVE-2026-81950HIGHCVSS 7.8EG 7.82026-09-08
Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-69725HIGHCVSS 7.8EG 7.82026-09-08
Double free in Windows Hello allows an authorized attacker to elevate privileges locally.
- CVE-2026-43622HIGHCVSS 7.8EG 7.82026-08-06
llama.cpp builds b1886 through b7445 contain a double free vulnerability in the LLaMA-Android JNI wrapper where new_1batch() allocates memory using malloc() while free_1batch() deallocates it using the C++ delete operator, causing heap met…
- CVE-2026-64447HIGHCVSS 7.8EG 7.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: staging: media: ipu7: fix double-free and use-after-free in error paths In both ipu7_isys_init() and ipu7_psys_init(), pdata is allocated and then passed to ipu7_bus_ini…
- CVE-2026-64377HIGHCVSS 7.8EG 7.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: cpufreq: qcom-cpufreq-hw: Fix possible double free qcom_cpufreq.data is allocated with devm_kzalloc() in probe() as an array of per-domain data. qcom_cpufreq_hw_cpu_init…
- CVE-2026-64242HIGHCVSS 7.8EG 7.82026-07-24
In the Linux kernel, the following vulnerability has been resolved: usb: gadget: net2280: Fix double free in probe error path usb_initialize_gadget() installs gadget_release() as the release callback for the embedded gadget device. The …
- CVE-2026-64224HIGHCVSS 7.8EG 7.82026-07-24
In the Linux kernel, the following vulnerability has been resolved: octeontx2-pf: fix double free in rvu_rep_rsrc_init() rvu_rep_rsrc_init() allocates queue memory before calling otx2_init_hw_resources(). When hardware resource setup fai…
- CVE-2026-64054HIGHCVSS 7.8EG 7.82026-07-19
In the Linux kernel, the following vulnerability has been resolved: net: shaper: reject duplicate leaves in GROUP request net_shaper_nl_group_doit() does not deduplicate NET_SHAPER_A_LEAVES entries. When userspace supplies the same leaf …
- CVE-2026-55132HIGHCVSS 7.8EG 7.82026-07-14
Double free in Microsoft Office Word allows an unauthorized attacker to execute code locally.
- CVE-2026-50361HIGHCVSS 7.8EG 7.82026-07-14
Double free in Microsoft Brokering File System allows an authorized attacker to elevate privileges locally.
- CVE-2026-55004HIGHCVSS 7.8EG 7.82026-07-14
Double free in Microsoft Printer Drivers allows an authorized attacker to elevate privileges locally.
- CVE-2026-53294HIGHCVSS 7.8EG 7.82026-06-26
In the Linux kernel, the following vulnerability has been resolved: mailbox: mailbox-test: don't free the reused channel The RX channel can be aliased to the TX channel if it has a different MMIO. This special case needs to be handled wh…
- CVE-2026-53286HIGHCVSS 7.8EG 7.82026-06-26
In the Linux kernel, the following vulnerability has been resolved: idpf: fix double free and use-after-free in aux device error paths When auxiliary_device_add() fails in idpf_plug_vport_aux_dev() or idpf_plug_core_aux_dev(), the err_au…
- CVE-2026-53233HIGHCVSS 7.8EG 7.82026-06-25
In the Linux kernel, the following vulnerability has been resolved: netdev: fix double-free in netdev_nl_bind_rx_doit() Sashiko flags that genlmsg_reply() always consumes the skb. The error path calls nlmsg_free(rsp) so we can't jump dir…
- CVE-2026-53067HIGHCVSS 7.8EG 7.82026-06-24
In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: pci-ep-msi: Fix error unwind and prevent double alloc pci_epf_alloc_doorbell() stores the allocated doorbell message array in epf->db_msg/epf->num_db befo…
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →