CWE-415— Double Free
The product calls free() twice on the same memory address.— MITRE CWE catalog
891 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-415page 18 of 18
- CVE-2026-64377HIGHCVSS 7.8EG 7.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: cpufreq: qcom-cpufreq-hw: Fix possible double free qcom_cpufreq.data is allocated with devm_kzalloc() in probe() as an array of per-domain data. qcom_cpufreq_hw_cpu_init…
- CVE-2026-64382HIGHCVSS 8.8EG 8.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_open() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_open_init() fails befor…
- CVE-2026-64383CRITICALCVSS 9.8EG 9.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_flush() replay SMB2_flush() keeps its response buffer bookkeeping across replay attempts. If a replayable flush response is received…
- CVE-2026-64384CRITICALCVSS 9.8EG 9.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix change notify replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_notify_init() fails befo…
- CVE-2026-64385CRITICALCVSS 9.8EG 9.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix double-free in SMB2_ioctl() replay A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_ioctl_init() fails bef…
- CVE-2026-64386CRITICALCVSS 9.8EG 9.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query_info() replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_info_init() fails b…
- CVE-2026-64387CRITICALCVSS 9.8EG 9.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: smb: client: fix query directory replay double-free A response-bearing attempt can return a replayable error and free its response buffer. If SMB2_query_directory_init()…
- CVE-2026-64447HIGHCVSS 7.8EG 7.82026-07-25
In the Linux kernel, the following vulnerability has been resolved: staging: media: ipu7: fix double-free and use-after-free in error paths In both ipu7_isys_init() and ipu7_psys_init(), pdata is allocated and then passed to ipu7_bus_ini…
- CVE-2026-64621HIGHCVSS 7.3EG 7.32026-07-20
FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a double-free vulnerability in freerdp_client_rdp_file_apply_to_settings() (client/common/file.c) when parsing the selectedmonitors field of a .rdp connection file. The MonitorId…
- CVE-2026-64832HIGHCVSS 8.8EG 8.82026-07-22
FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability in the NVIDIA NVDEC hardware decoder within libavcodec/nvdec.c that allows attackers to trigger memory corruption by supplying a crafted video file. When no decoder surf…
- CVE-2026-65780HIGHCVSS 7.0EG 7.02026-08-11
Double free in Windows Autopilot allows an authorized attacker to elevate privileges locally.
- CVE-2026-66032HIGHCVSS 8.8EG 8.82026-07-24
libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-free vulnerability in the sftp_open() function in src/sftp.c that allows a malicious SSH server to corrupt the heap of any authenticated client opening an SFTP session. Whe…
- CVE-2026-66373HIGHCVSS 7.5EG 7.52026-07-25
Redis before 8.8.0, in the unusual case where an authenticated attacker can execute RESTORE, allows remote code execution via a RESTORE payload where the same NACK (pending entry) is referenced by more than one consumer, because deleting b…
- CVE-2026-6654MEDIUMCVSS 5.1EG 5.12026-04-20
Double-Free / Use-After-Free (UAF) in the `IntoIter::drop` and `ThinVec::clear` functions in the thin_vec crate. A panic in `ptr::drop_in_place` skips setting the length to zero.
- CVE-2026-69292HIGHCVSS 7.0EG 7.02026-09-08
Double free in Remote Desktop Gateway Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69309HIGHCVSS 7.0EG 7.02026-09-08
Double free in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
- CVE-2026-69322HIGHCVSS 8.0EG 8.02026-09-08
Double free in Microsoft Windows Search Component allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69337HIGHCVSS 7.1EG 7.12026-09-08
Double free in Windows Registry allows an authorized attacker to elevate privileges over a network.
- CVE-2026-69398HIGHCVSS 7.0EG 7.02026-09-08
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-69725HIGHCVSS 7.8EG 7.82026-09-08
Double free in Windows Hello allows an authorized attacker to elevate privileges locally.
- CVE-2026-69876HIGHCVSS 8.0EG 8.02026-09-08
Use after free in Windows DHCP Server allows an authorized attacker to execute code over an adjacent network.
- CVE-2026-70562HIGHCVSS 7.0EG 7.02026-09-08
Double free in Windows Audio Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-70567HIGHCVSS 7.0EG 7.02026-09-08
Double free in Windows Display Enhancement Service allows an authorized attacker to elevate privileges locally.
- CVE-2026-71338MEDIUMCVSS 6.4EG 6.42026-09-08
Double free in Windows Failover Cluster allows an authorized attacker to elevate privileges locally.
- CVE-2026-71351HIGHCVSS 7.0EG 7.02026-09-08
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-71353HIGHCVSS 7.0EG 7.02026-09-08
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- CVE-2026-72958HIGHCVSS 8.2EG 8.22026-09-08
Double free in Windows Credential Guard allows an authorized attacker to elevate privileges locally.
- CVE-2026-75159MEDIUMCVSS 5.9EG 5.92026-08-27
An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication may cause mongosqld to terminate when a crafted authentication exchange encounters a specific GSSAPI error-handling cond…
- CVE-2026-77493CRITICALCVSS 9.8EG 9.82026-09-08
Double free in Microsoft Graphics Component allows an unauthorized attacker to execute code over a network.
- CVE-2026-77504HIGHCVSS 8.8EG 8.82026-09-08
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-79907HIGHCVSS 7.8EG 7.82026-09-08
Acrobat Reader is affected by a Double Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- CVE-2026-80080HIGHCVSS 8.8EG 8.82026-09-08
Double free in Microsoft Office Word allows an unauthorized attacker to execute code over a network.
- CVE-2026-81950HIGHCVSS 7.8EG 7.82026-09-08
Double free in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
- CVE-2026-82325MEDIUMCVSS 6.8EG 6.82026-09-07
A use-after-free vulnerability in the OpenVPN ovpn-dco-win driver version 2.5.0 through 2.8.6 allows local authenticated users to cause a system crash via crafted control messages
- CVE-2026-82677LOWCVSS 2.4EG 2.42026-08-31
A vulnerability was determined in valkey-io valkey 9.1.0. Impacted is the function moduleTimerHandler of the file src/module.c of the component Module Timer Subsystem. This manipulation causes double free. The attack can be initiated remot…
- CVE-2026-84558MEDIUMCVSS 5.5EG 5.52026-09-14
A double free issue was addressed with improved memory management. This issue is fixed in macOS Golden Gate 27. An app may be able to cause unexpected system termination.
- CVE-2026-84561CRITICALCVSS 9.8EG 9.82026-09-14
A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.7 and iPadOS 26.7, iOS 27 and iPadOS 27, macOS Golden Gate 27, macOS Sequoia 15.8, macOS Tahoe 26.7, tvOS 27, visionOS 27, watchOS 27. An app …
- CVE-2026-84964MEDIUMCVSS 5.9EG 5.92026-09-03
A double free in the OpenSSL-based TLS certificate revocation checking path of the MongoDB C Driver can be reached by a TLS endpoint that the client already trusts. During the handshake, specially formed certificate data can cause the same…
- CVE-2026-85921HIGHCVSS 8.2EG 8.22026-09-14
Double free in Windows Secure Kernel Mode allows an authorized attacker to elevate privileges locally.
- CVE-2026-87585HIGHCVSS 8.8EG 8.82026-09-09
Double free in PDFium in Google Chrome on on Windows prior to 153.0.8010.36 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted PDF file. (Chromium security severity: High)
- CVE-2026-8925CRITICALCVSS 9.8EG 9.82026-07-03
The curl logic that works with SASL authentication could end up cleaning up the GSASL context *twice* without clearing the pointer in between, making it `free()` the same pointer twice.
Map vulnerabilities like CWE-415 to your infrastructure
EchelonGraph correlates every CVE — across CWE-415 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →