Threadlinqs IntelligenceStart free

Weakness · VariantCWE-415

CWE-415: Double Free

Likelihood of exploit: HighVariant

As of 2026-10-05, CWE-415 (Double Free) underlies 3 CVEs tracked by Threadlinqs, none of them in the CISA Known Exploited Vulnerabilities catalog, and is cited by 11 tracked threats. MITRE rates its likelihood of exploit as High.

CVEs
3Mapped to CWE-415
CISA KEV
0None listed yet
Critical
0CVSS v3 critical CVEs
Threats
11Tracked campaigns citing it
Likelihood
HighMITRE likelihood of exploit

Last updated:

What is CWE-415?

The product calls free() twice on the same memory address.

CWE-415 is a variant-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Language: Memory-Unsafe; Language: C; Language: C++.

Source: MITRE CWE (CWE-415 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.

Consequences

  • Integrity, Confidentiality, Availability — Modify Memory, Execute Unauthorized Code or Commands. When a program calls free() twice with the same argument, the program's memory management data structures may become corrupted, potentially leading to the reading or modification of unexpected memory addresses. This corruption can cause the program to crash or, in some circumstances, cause two later calls to malloc() to return the same pointer. If malloc() returns the same value twice and the program later gives the attacker control over the data that is written into this doubly-allocated…

Source: MITRE CWE, common consequences.

How CWE-415 is exploited in the wild

Threadlinqs maps 3 CVEs to CWE-415, published between 2026-05-04 and 2026-09-14. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 3 high. The highest EPSS score in the set is 0.9% (CVE-2026-23918), the modelled probability of exploitation in the next 30 days. 11 tracked threats reference CWE-415 directly or through a CVE it covers; the most recent is “Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing Flaws Across Azure and Copilot AI Products, Plus a Windows Secure Kernel EoP (CVE-2026-85921)” (2026-09-18). Affected products concentrate in Apache Software Foundation (1), Microsoft (1), strongSwan (1).

Vulnerabilities (CVEs)

All 3 CVEs mapped to CWE-415, CISA KEV first, then by CVSS score.

Affected vendors

Threat activity

11 tracked threats cite CWE-415:

Mitigations

  • Architecture and Design: Choose a language that provides automatic memory management.
  • Implementation: Ensure that each allocation is freed only once. After freeing a chunk, set the pointer to NULL to ensure the pointer cannot be freed again. In complicated error conditions, be sure that clean-up routines respect the state of allocation properly. If the language is object oriented, ensure that object destructors delete each chunk of memory only once.
  • Implementation: Use a static analysis tool to find double free instances.

Source: MITRE CWE, potential mitigations.

Detection methods (MITRE CWE)

  • Fuzzing (effectiveness: High): Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with random inputs, it is often capable of generating unexpected results such as crashes, memory corruption, or resource consumption. Fuzzing effectively produces repeatable test cases that clearly indicate bugs, which helps developers to diagnose the issues.
  • Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
  • Automated Dynamic Analysis (effectiveness: Moderate): Use tools that are integrated during compilation to insert runtime error-checking mechanisms related to memory safety errors, such as AddressSanitizer (ASan) for C/C++ [REF-1518].

Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.