CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
904 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 9 of 19
- CVE-2021-47589HIGHCVSS 7.8EG 7.82024-06-19
In the Linux kernel, the following vulnerability has been resolved: igbvf: fix double free in `igbvf_probe` In `igbvf_probe`, if register_netdev() fails, the program will go to label err_hw_init, and then to label err_ioremap. In free_ne…
- CVE-2024-36973HIGHCVSS 7.8EG 7.82024-06-17
In the Linux kernel, the following vulnerability has been resolved: misc: microchip: pci1xxxx: fix double free in the error handling of gp_aux_bus_probe() When auxiliary_device_add() returns error and then calls auxiliary_device_uninit()…
- CVE-2024-36940HIGHCVSS 7.8EG 7.82024-05-30
In the Linux kernel, the following vulnerability has been resolved: pinctrl: core: delete incorrect free in pinctrl_enable() The "pctldev" struct is allocated in devm_pinctrl_register_and_init(). It's a devm_ managed pointer that is free…
- CVE-2021-47564HIGHCVSS 7.8EG 7.82024-05-24
In the Linux kernel, the following vulnerability has been resolved: net: marvell: prestera: fix double free issue on err path fix error path handling in prestera_bridge_port_join() that cases prestera driver to crash (see below). Trace…
- CVE-2021-47483HIGHCVSS 7.8EG 7.82024-05-22
In the Linux kernel, the following vulnerability has been resolved: regmap: Fix possible double-free in regcache_rbtree_exit() In regcache_rbtree_insert_to_block(), when 'present' realloc failed, the 'blk' which is supposed to assign to …
- CVE-2023-52851HIGHCVSS 7.8EG 7.82024-05-21
In the Linux kernel, the following vulnerability has been resolved: IB/mlx5: Fix init stage error handling to avoid double free of same QP and UAF In the unlikely event that workqueue allocation fails and returns NULL in mlx5_mkey_cache_…
- CVE-2023-52795HIGHCVSS 7.8EG 7.82024-05-21
In the Linux kernel, the following vulnerability has been resolved: vhost-vdpa: fix use after free in vhost_vdpa_probe() The put_device() calls vhost_vdpa_release_dev() which calls ida_simple_remove() and frees "v". So this call to ida_…
- CVE-2024-35856HIGHCVSS 7.8EG 7.82024-05-17
In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: mediatek: Fix double free of skb in coredump hci_devcd_append() would free the skb on error so the caller don't have to free it again otherwise it woul…
- CVE-2024-35847HIGHCVSS 7.8EG 7.82024-05-17
In the Linux kernel, the following vulnerability has been resolved: irqchip/gic-v3-its: Prevent double free on error The error handling path in its_vpe_irq_domain_alloc() causes a double free when its_vpe_init() fails after successfully …
- CVE-2023-52691HIGHCVSS 7.8EG 7.82024-05-17
In the Linux kernel, the following vulnerability has been resolved: drm/amd/pm: fix a double-free in si_dpm_init When the allocation of adev->pm.dpm.dyn_state.vddc_dependency_on_dispclk.entries fails, amdgpu_free_extended_power_table is …
- CVE-2023-52688HIGHCVSS 7.8EG 7.82024-05-17
In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: fix the error handler of rfkill config When the core rfkill config throws error, it should free the allocated resources. Currently it is not freeing the co…
- CVE-2023-52679HIGHCVSS 7.8EG 7.82024-05-17
In the Linux kernel, the following vulnerability has been resolved: of: Fix double free in of_parse_phandle_with_args_map In of_parse_phandle_with_args_map() the inner loop that iterates through the map entries calls of_node_put(new) to …
- CVE-2023-52667HIGHCVSS 7.8EG 7.82024-05-17
In the Linux kernel, the following vulnerability has been resolved: net/mlx5e: fix a potential double-free in fs_any_create_groups When kcalloc() for ft->g succeeds but kvzalloc() for in fails, fs_any_create_groups() will free ft->g. How…
- CVE-2023-52664HIGHCVSS 7.8EG 7.82024-05-17
In the Linux kernel, the following vulnerability has been resolved: net: atlantic: eliminate double free in error handling logic Driver has a logic leak in ring data allocation/free, where aq_ring_free could be called multiple times on s…
- CVE-2024-27433HIGHCVSS 7.8EG 7.82024-05-17
In the Linux kernel, the following vulnerability has been resolved: clk: mediatek: mt7622-apmixedsys: Fix an error handling path in clk_mt8135_apmixed_probe() 'clk_data' is allocated with mtk_devm_alloc_clk_data(). So calling mtk_free_cl…
- CVE-2024-30027HIGHCVSS 7.8EG 7.82024-05-14
NTFS Elevation of Privilege Vulnerability
- CVE-2024-27392HIGHCVSS 7.8EG 7.82024-05-01
In the Linux kernel, the following vulnerability has been resolved: nvme: host: fix double-free of struct nvme_id_ns in ns_update_nuse() When nvme_identify_ns() fails, it frees the pointer to the struct nvme_id_ns before it returns. Howe…
- CVE-2024-26932HIGHCVSS 7.8EG 7.82024-05-01
In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: fix double-free issue in tcpm_port_unregister_pd() When unregister pd capabilitie in tcpm, KASAN will capture below double -free issue. The root cause …
- CVE-2024-26930HIGHCVSS 7.8EG 7.82024-05-01
In the Linux kernel, the following vulnerability has been resolved: scsi: qla2xxx: Fix double free of the ha->vp_map pointer Coverity scan reported potential risk of double free of the pointer ha->vp_map. ha->vp_map was freed in qla2x00…
- CVE-2022-48649HIGHCVSS 7.8EG 7.82024-04-28
In the Linux kernel, the following vulnerability has been resolved: mm/slab_common: fix possible double free of kmem_cache When doing slub_debug test, kfence's 'test_memcache_typesafe_by_rcu' kunit test case cause a use-after-free error:…
- CVE-2024-26257HIGHCVSS 7.8EG 7.82024-04-09
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2024-26792HIGHCVSS 7.8EG 7.82024-04-04
In the Linux kernel, the following vulnerability has been resolved: btrfs: fix double free of anonymous device after snapshot creation failure When creating a snapshot we may do a double free of an anonymous device in case there's an err…
- CVE-2024-26782HIGHCVSS 7.8EG 7.82024-04-04
In the Linux kernel, the following vulnerability has been resolved: mptcp: fix double-free on socket dismantle when MPTCP server accepts an incoming connection, it clones its listener socket. However, the pointer to 'inet_opt' for the ne…
- CVE-2024-26748HIGHCVSS 7.8EG 7.82024-04-03
In the Linux kernel, the following vulnerability has been resolved: usb: cdns3: fix memory double free when handle zero packet 829 if (request->complete) { 830 spin_unlock(&priv_dev->lock); 831 usb_gadget_giveback_requ…
- CVE-2024-26704HIGHCVSS 7.8EG 7.82024-04-03
In the Linux kernel, the following vulnerability has been resolved: ext4: fix double-free of blocks due to wrong extents moved_len In ext4_move_extents(), moved_len is only updated when all moves are successfully executed, and only disca…
- CVE-2024-26694HIGHCVSS 7.8EG 7.82024-04-03
In the Linux kernel, the following vulnerability has been resolved: wifi: iwlwifi: fix double-free bug The storage for the TLV PC register data wasn't done like all the other storage in the drv->fw area, which is cleared at the end of de…
- CVE-2024-26653HIGHCVSS 7.8EG 7.82024-04-01
In the Linux kernel, the following vulnerability has been resolved: usb: misc: ljca: Fix double free in error handling path When auxiliary_device_add() returns error and then calls auxiliary_device_uninit(), callback function ljca_auxdev…
- CVE-2021-47123HIGHCVSS 7.8EG 7.82024-03-15
In the Linux kernel, the following vulnerability has been resolved: io_uring: fix ltout double free on completion race Always remove linked timeout on io_link_timeout_fn() from the master request link list, otherwise we may get use-after…
- CVE-2021-47082HIGHCVSS 7.8EG 7.82024-03-04
In the Linux kernel, the following vulnerability has been resolved: tun: avoid double free in tun_free_netdev Avoid double free in tun_free_netdev() by moving the dev->tstats and tun->security allocs to a new ndo_init routine (tun_net_in…
- CVE-2020-36785HIGHCVSS 7.8EG 7.82024-02-28
In the Linux kernel, the following vulnerability has been resolved: media: atomisp: Fix use after free in atomisp_alloc_css_stat_bufs() The "s3a_buf" is freed along with all the other items on the "asd->s3a_stats" list. It leads to a do…
- CVE-2021-46938HIGHCVSS 7.8EG 7.82024-02-27
In the Linux kernel, the following vulnerability has been resolved: dm rq: fix double free of blk_mq_tag_set in dev remove after table load fails When loading a device-mapper table for a request-based mapped device, and the allocation/in…
- CVE-2023-52439HIGHCVSS 7.8EG 7.82024-02-20
In the Linux kernel, the following vulnerability has been resolved: uio: Fix use-after-free in uio_open core-1 core-2 ------------------------------------------------------- uio_unregister_device uio_open idev = idr_find() device…
- CVE-2023-40103HIGHCVSS 7.8EG 7.82023-12-04
In multiple locations, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.
- CVE-2023-48013HIGHCVSS 7.8EG 7.82023-11-15
GPAC v2.3-DEV-rev566-g50c2ab06f-master was discovered to contain a double free via the gf_filterpacket_del function at /gpac/src/filter_core/filter.c.
- CVE-2023-45679HIGHCVSS 7.8EG 7.82023-10-21
stb_vorbis is a single file MIT licensed library for processing ogg vorbis files. A crafted file may trigger memory allocation failure in `start_decoder`. In that case the function returns early, but some of the pointers in `f->comment_lis…
- CVE-2023-36420HIGHCVSS 7.8EG 7.82023-10-10
Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability
- CVE-2023-36418HIGHCVSS 7.8EG 7.82023-10-10
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
- CVE-2023-41374HIGHCVSS 7.8EG 7.82023-09-20
Double free issue exists in Kostac PLC Programming Software Version 1.6.11.0 and earlier. Arbitrary code may be executed by having a user open a specially crafted project file which was saved using Kostac PLC Programming Software Version 1…
- CVE-2023-35371HIGHCVSS 7.8EG 7.82023-08-08
Microsoft Office Remote Code Execution Vulnerability
- CVE-2023-33161HIGHCVSS 7.8EG 7.82023-07-11
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2023-33137HIGHCVSS 7.8EG 7.82023-06-14
Microsoft Excel Remote Code Execution Vulnerability
- CVE-2023-29366HIGHCVSS 7.8EG 7.82023-06-14
Windows Geolocation Service Remote Code Execution Vulnerability
- CVE-2023-21106HIGHCVSS 7.8EG 7.82023-05-15
In adreno_set_param of adreno_gpu.c, there is a possible memory corruption due to a double free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitati…
- CVE-2023-28464HIGHCVSS 7.8EG 7.82023-03-31
hci_conn_cleanup in net/bluetooth/hci_conn.c in the Linux kernel through 6.2.9 has a use-after-free (observed in hci_conn_hash_flush) because of calls to hci_dev_put and hci_conn_put. There is a double free that may lead to privilege escal…
- CVE-2022-4744HIGHCVSS 7.8EG 7.82023-03-30
A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or po…
- CVE-2023-21030HIGHCVSS 7.8EG 7.82023-03-24
In Confirmation of keystore_cli_v2.cpp, there is a possible way to corrupt memory due to a double free. This could lead to local escalation of privilege in an unprivileged process with no additional execution privileges needed. User intera…
- CVE-2023-23402HIGHCVSS 7.8EG 7.82023-03-14
Windows Media Remote Code Execution Vulnerability
- CVE-2022-40683HIGHCVSS 7.8EG 7.82023-02-16
A double free in Fortinet FortiWeb version 7.0.0 through 7.0.3 may allows attacker to execute unauthorized code or commands via specially crafted commands
- CVE-2022-40304HIGHCVSS 7.8EG 7.82022-11-23
An issue was discovered in libxml2 before 2.10.3. Certain invalid XML entity definitions can corrupt a hash table key, potentially leading to subsequent logic errors. In one case, a double-free can be provoked.
- CVE-2022-3238HIGHCVSS 7.8EG 7.82022-11-14
A double-free flaw was found in the Linux kernel’s NTFS3 subsystem in how a user triggers remount and umount simultaneously. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →