CWE-763
AllowedRelease of Invalid Pointer or Reference
Abstraction: Base · Status: Incomplete
The product attempts to return a memory resource to the system, but it calls the wrong release function or calls the appropriate release function incorrectly.
124 vulnerabilities reference this CWE, most recent first.
GHSA-82F5-GHC6-RJ5C
Vulnerability from github – Published: 2023-07-06 21:15 – Updated: 2024-04-04 05:46Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to bypass the "access_ok" check and pass a kernel pointer to copy_from_user(). This would allow an attacker to leak information. We recommend upgrading beyond commit 74e19ef0ff8061ef55957c3abd71614ef0f42f47
{
"affected": [],
"aliases": [
"CVE-2023-0459"
],
"database_specific": {
"cwe_ids": [
"CWE-763"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-05-25T14:15:09Z",
"severity": "MODERATE"
},
"details": "Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to bypass the \"access_ok\" check and pass a kernel pointer to copy_from_user(). This would allow an attacker to leak information. We recommend upgrading beyond commit\u00a074e19ef0ff8061ef55957c3abd71614ef0f42f47",
"id": "GHSA-82f5-ghc6-rj5c",
"modified": "2024-04-04T05:46:54Z",
"published": "2023-07-06T21:15:05Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-0459"
},
{
"type": "WEB",
"url": "https://github.com/torvalds/linux/commit/4b842e4e25b12951fa10dedb4bc16bc47e3b850c"
},
{
"type": "WEB",
"url": "https://github.com/torvalds/linux/commit/74e19ef0ff8061ef55957c3abd71614ef0f42f47"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
}
]
}
GHSA-8626-CQQJ-MFFF
Vulnerability from github – Published: 2026-09-08 12:31 – Updated: 2026-09-28 15:31A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.
{
"affected": [],
"aliases": [
"CVE-2026-74860"
],
"database_specific": {
"cwe_ids": [
"CWE-763"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-08T12:16:58Z",
"severity": "HIGH"
},
"details": "A flaw was found in libxml2 with Python bindings enabled. A remote attacker could exploit this vulnerability by providing a specially crafted XML document containing a Document Type Definition (DTD) with enumerated attribute values. This triggers a double-free error in the SAX attributeDecl callback handler, where a string is freed twice. This flaw can lead to a denial of service (DoS) due to a reproducible crash in Python applications using the libxml2 SAX bindings.",
"id": "GHSA-8626-cqqj-mfff",
"modified": "2026-09-28T15:31:20Z",
"published": "2026-09-08T12:31:30Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-74860"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:64463"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:71585"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:71586"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:71641"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:72470"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:72475"
},
{
"type": "WEB",
"url": "https://access.redhat.com/errata/RHSA-2026:72476"
},
{
"type": "WEB",
"url": "https://access.redhat.com/security/cve/CVE-2026-74860"
},
{
"type": "WEB",
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=2529697"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-89MG-6P9G-4JFJ
Vulnerability from github – Published: 2023-03-19 03:30 – Updated: 2024-08-22 21:31In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before replaying logs.
{
"affected": [],
"aliases": [
"CVE-2022-48425"
],
"database_specific": {
"cwe_ids": [
"CWE-763"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-03-19T03:15:00Z",
"severity": "HIGH"
},
"details": "In the Linux kernel through 6.2.7, fs/ntfs3/inode.c has an invalid kfree because it does not validate MFT flags before replaying logs.",
"id": "GHSA-89mg-6p9g-4jfj",
"modified": "2024-08-22T21:31:27Z",
"published": "2023-03-19T03:30:25Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-48425"
},
{
"type": "WEB",
"url": "https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=467333af2f7b95eeaa61a5b5369a80063cd971fd"
},
{
"type": "WEB",
"url": "https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/fs/ntfs3?id=467333af2f7b95eeaa61a5b5369a80063cd971fd"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230413-0006"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-8CGH-48G2-RJ4J
Vulnerability from github – Published: 2026-01-16 00:30 – Updated: 2026-01-16 00:30Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers() which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. : Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series/imageCLASS X LBP1238 II/imageCLASS MF450 Series/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II firmware v06.02 and earlier sold in US.i-SENSYS LBP630C Series/i-SENSYS MF650C Series/i-SENSYS LBP230 Series/1238P II/1238Pr II/i-SENSYS MF450 Series/i-SENSYS MF550 Series/1238i II/1238iF II/imageRUNNER 1643i II/imageRUNNER 1643iF II firmware v06.02 and earlier sold in Europe.
{
"affected": [],
"aliases": [
"CVE-2025-14233"
],
"database_specific": {
"cwe_ids": [
"CWE-763"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-01-16T00:16:27Z",
"severity": "CRITICAL"
},
"details": "Invalid free in CPCA file deletion processing on Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series/imageCLASS X LBP1238 II/imageCLASS MF450 Series/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II firmware v06.02 and earlier sold in US.i-SENSYS LBP630C Series/i-SENSYS MF650C Series/i-SENSYS LBP230 Series/1238P II/1238Pr II/i-SENSYS MF450 Series/i-SENSYS MF550 Series/1238i II/1238iF II/imageRUNNER 1643i II/imageRUNNER 1643iF II firmware v06.02 and earlier sold in Europe.",
"id": "GHSA-8cgh-48g2-rj4j",
"modified": "2026-01-16T00:30:55Z",
"published": "2026-01-16T00:30:55Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2025-14233"
},
{
"type": "WEB",
"url": "https://canon.jp/support/support-info/260115vulnerability-response"
},
{
"type": "WEB",
"url": "https://psirt.canon/advisory-information/cp2026-001"
},
{
"type": "WEB",
"url": "https://www.canon-europe.com/support/product-security"
},
{
"type": "WEB",
"url": "https://www.usa.canon.com/support/canon-product-advisories/Service-Notice-Regarding-Remediation-Measure-Against-Potential-Buffer-Overflow-Vulnerability-in-Laser-Printers-and-Small-Office-Multifunctional-Printers"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"type": "CVSS_V4"
}
]
}
GHSA-8MP8-J92P-F4Q7
Vulnerability from github – Published: 2023-04-24 06:31 – Updated: 2024-03-25 03:31An issue was discovered in drivers/tty/n_gsm.c in the Linux kernel 6.2. There is a sleeping function called from an invalid context in gsmld_write, which will block the kernel.
{
"affected": [],
"aliases": [
"CVE-2023-31082"
],
"database_specific": {
"cwe_ids": [
"CWE-763"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-04-24T06:15:07Z",
"severity": "MODERATE"
},
"details": "An issue was discovered in drivers/tty/n_gsm.c in the Linux kernel 6.2. There is a sleeping function called from an invalid context in gsmld_write, which will block the kernel.",
"id": "GHSA-8mp8-j92p-f4q7",
"modified": "2024-03-25T03:31:43Z",
"published": "2023-04-24T06:31:20Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2023-31082"
},
{
"type": "WEB",
"url": "https://bugzilla.suse.com/show_bug.cgi?id=1210781"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/all/CA+UBctCZok5FSQ=LPRA+A-jocW=L8FuMVZ_7MNqhh483P5yN8A%40mail.gmail.com"
},
{
"type": "WEB",
"url": "https://lore.kernel.org/all/CA+UBctCZok5FSQ=LPRA+A-jocW=L8FuMVZ_7MNqhh483P5yN8A@mail.gmail.com"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230929-0003"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-8V78-CGM6-V8H8
Vulnerability from github – Published: 2026-09-01 15:31 – Updated: 2026-09-02 00:31Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.
{
"affected": [],
"aliases": [
"CVE-2026-84131"
],
"database_specific": {
"cwe_ids": [
"CWE-763"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2026-09-01T13:20:07Z",
"severity": "HIGH"
},
"details": "Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed in Firefox 155, Firefox ESR 115.40, Firefox ESR 140.15, and Firefox ESR 153.2.",
"id": "GHSA-8v78-cgm6-v8h8",
"modified": "2026-09-02T00:31:28Z",
"published": "2026-09-01T15:31:08Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2026-84131"
},
{
"type": "WEB",
"url": "https://bugzilla.mozilla.org/show_bug.cgi?id=2060008"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2026-82"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2026-83"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2026-84"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2026-85"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2026-86"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2026-87"
},
{
"type": "WEB",
"url": "https://www.mozilla.org/security/advisories/mfsa2026-88"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-8VJX-3VGX-66MX
Vulnerability from github – Published: 2023-01-11 15:30 – Updated: 2026-09-01 18:30There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won't use current->nsproxy, so its reference counter is not increased. This assumption is not always true as calling io_splice on specific files will call the get_uts function which will use current->nsproxy leading to invalidly decreasing its reference counter later causing the use-after-free vulnerability. We recommend upgrading to version 5.10.160 or above
{
"affected": [],
"aliases": [
"CVE-2022-4696"
],
"database_specific": {
"cwe_ids": [
"CWE-416",
"CWE-763"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2023-01-11T13:15:00Z",
"severity": "HIGH"
},
"details": "There exists a use-after-free vulnerability in the Linux kernel through io_uring and the IORING_OP_SPLICE operation. If IORING_OP_SPLICE is missing the IO_WQ_WORK_FILES flag, which signals that the operation won\u0027t use current-\u003ensproxy, so its reference counter is not increased. This assumption is not always true as calling io_splice on specific files will call the get_uts function which will use current-\u003ensproxy leading to invalidly decreasing its reference counter later causing the use-after-free vulnerability. We recommend upgrading to version 5.10.160 or above",
"id": "GHSA-8vjx-3vgx-66mx",
"modified": "2026-09-01T18:30:27Z",
"published": "2023-01-11T15:30:42Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-4696"
},
{
"type": "WEB",
"url": "https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git/commit/?h=linux-5.10.y\u0026id=75454b4bbfc7e6a4dd8338556f36ea9107ddf61a"
},
{
"type": "WEB",
"url": "https://kernel.dance/#75454b4bbfc7e6a4dd8338556f36ea9107ddf61a"
},
{
"type": "WEB",
"url": "https://security.netapp.com/advisory/ntap-20230223-0003"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-8W89-3RVR-HM3W
Vulnerability from github – Published: 2022-05-01 18:22 – Updated: 2025-04-09 03:45Opera before 9.23 allows remote attackers to execute arbitrary code via crafted Javascript that triggers a "virtual function call on an invalid pointer."
{
"affected": [],
"aliases": [
"CVE-2007-4367"
],
"database_specific": {
"cwe_ids": [
"CWE-763"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2007-08-15T23:17:00Z",
"severity": "HIGH"
},
"details": "Opera before 9.23 allows remote attackers to execute arbitrary code via crafted Javascript that triggers a \"virtual function call on an invalid pointer.\"",
"id": "GHSA-8w89-3rvr-hm3w",
"modified": "2025-04-09T03:45:12Z",
"published": "2022-05-01T18:22:52Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2007-4367"
},
{
"type": "WEB",
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/36039"
},
{
"type": "WEB",
"url": "http://lists.opensuse.org/opensuse-security-announce/2007-08/msg00006.html"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/26477"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/26545"
},
{
"type": "WEB",
"url": "http://secunia.com/advisories/26635"
},
{
"type": "WEB",
"url": "http://security.gentoo.org/glsa/glsa-200708-17.xml"
},
{
"type": "WEB",
"url": "http://www.opera.com/support/search/view/865"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/25331"
},
{
"type": "WEB",
"url": "http://www.securitytracker.com/id?1018572"
},
{
"type": "WEB",
"url": "http://www.vupen.com/english/advisories/2007/2904"
}
],
"schema_version": "1.4.0",
"severity": []
}
GHSA-957W-PHR7-H5MC
Vulnerability from github – Published: 2022-05-13 01:40 – Updated: 2022-05-13 01:40A elevation of privilege vulnerability in the Android media framework (mpeg4 encoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36075363.
{
"affected": [],
"aliases": [
"CVE-2017-0731"
],
"database_specific": {
"cwe_ids": [
"CWE-763"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2017-08-09T21:29:00Z",
"severity": "HIGH"
},
"details": "A elevation of privilege vulnerability in the Android media framework (mpeg4 encoder). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36075363.",
"id": "GHSA-957w-phr7-h5mc",
"modified": "2022-05-13T01:40:34Z",
"published": "2022-05-13T01:40:34Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2017-0731"
},
{
"type": "WEB",
"url": "https://source.android.com/security/bulletin/2017-08-01"
},
{
"type": "WEB",
"url": "http://www.securityfocus.com/bid/100204"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
}
]
}
GHSA-968G-C3P8-6HVF
Vulnerability from github – Published: 2022-08-07 00:00 – Updated: 2022-08-12 00:01Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.
{
"affected": [],
"aliases": [
"CVE-2022-37451"
],
"database_specific": {
"cwe_ids": [
"CWE-763"
],
"github_reviewed": false,
"github_reviewed_at": null,
"nvd_published_at": "2022-08-06T18:15:00Z",
"severity": "HIGH"
},
"details": "Exim before 4.96 has an invalid free in pam_converse in auths/call_pam.c because store_free is not used after store_malloc.",
"id": "GHSA-968g-c3p8-6hvf",
"modified": "2022-08-12T00:01:27Z",
"published": "2022-08-07T00:00:28Z",
"references": [
{
"type": "ADVISORY",
"url": "https://nvd.nist.gov/vuln/detail/CVE-2022-37451"
},
{
"type": "WEB",
"url": "https://github.com/Exim/exim/commit/51be321b27825c01829dffd90f11bfff256f7e42"
},
{
"type": "WEB",
"url": "https://cwe.mitre.org/data/definitions/762.html"
},
{
"type": "WEB",
"url": "https://github.com/Exim/exim/compare/exim-4.95...exim-4.96"
},
{
"type": "WEB",
"url": "https://github.com/Exim/exim/wiki/EximSecurity"
},
{
"type": "WEB",
"url": "https://github.com/ivd38/exim_invalid_free"
},
{
"type": "WEB",
"url": "https://lists.exim.org/lurker/message/20220625.141825.d6de6074.en.html"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/LETR5CVDPFOFQHXCJP6NFLG52JZHQYDY"
},
{
"type": "WEB",
"url": "https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/XSWDF4QEXD4TDWQLYQOWCHBJKTDQR4Z7"
},
{
"type": "WEB",
"url": "https://www.exim.org/static/doc/security"
},
{
"type": "WEB",
"url": "https://www.openwall.com/lists/oss-security/2022/08/06/1"
}
],
"schema_version": "1.4.0",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
}
]
}
Mitigation
Only call matching memory management functions. Do not mix and match routines. For example, when you allocate a buffer with malloc(), dispose of the original pointer with free().
Mitigation
When programming in C++, consider using smart pointers provided by the boost library to help correctly and consistently manage memory.
Mitigation MIT-4.6
Strategy: Libraries or Frameworks
- Use a vetted library or framework that does not allow this weakness to occur or provides constructs that make this weakness easier to avoid.
- For example, glibc in Linux provides protection against free of invalid pointers.
Mitigation
Use a language that provides abstractions for memory allocation and deallocation.
No CAPEC attack patterns related to this CWE.