What is CWE-415?
The product calls free() twice on the same memory address.
CWE-415 is a variant-level weakness in MITRE’s Common Weakness Enumeration, with a MITRE likelihood of exploit of High. Applicable platforms: Language: Memory-Unsafe; Language: C; Language: C++.
Source: MITRE CWE (CWE-415 definition, reproduced verbatim). Counts and linkage below are Threadlinqs data.
Consequences
- Integrity, Confidentiality, Availability — Modify Memory, Execute Unauthorized Code or Commands. When a program calls free() twice with the same argument, the program's memory management data structures may become corrupted, potentially leading to the reading or modification of unexpected memory addresses. This corruption can cause the program to crash or, in some circumstances, cause two later calls to malloc() to return the same pointer. If malloc() returns the same value twice and the program later gives the attacker control over the data that is written into this doubly-allocated…
Source: MITRE CWE, common consequences.
How CWE-415 is exploited in the wild
Threadlinqs maps 3 CVEs to CWE-415, published between 2026-05-04 and 2026-09-14. None of them is in the CISA KEV catalog yet. By CVSS v3 severity the set splits into 3 high. The highest EPSS score in the set is 0.9% (CVE-2026-23918), the modelled probability of exploitation in the next 30 days. 11 tracked threats reference CWE-415 directly or through a CVE it covers; the most recent is “Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing Flaws Across Azure and Copilot AI Products, Plus a Windows Secure Kernel EoP (CVE-2026-85921)” (2026-09-18). Affected products concentrate in Apache Software Foundation (1), Microsoft (1), strongSwan (1).
Vulnerabilities (CVEs)
All 3 CVEs mapped to CWE-415, CISA KEV first, then by CVSS score.
- CVE-2026-23918 — CVSS 8.8 high · EPSS 0.9% · published 2026-05-04
- CVE-2026-85921 — CVSS 8.2 high · EPSS 0.2% · published 2026-09-14
- CVE-2026-47895 — CVSS 7.5 high · EPSS 0.4% · published 2026-08-22
Affected vendors
- Apache Software Foundation — 1 CVE
- Microsoft — 1 CVE
- strongSwan — 1 CVE
Threat activity
11 tracked threats cite CWE-415:
- Microsoft September 2026 Cloud Disclosure: 18 Elevation-of-Privilege, Information-Disclosure, and Spoofing Flaws Across Azure and Copilot AI Products, Plus a Windows Secure Kernel EoP (CVE-2026-85921)CRITICAL
- Multiple Fortinet FortiOS Vulnerabilities (incl. CVE-2024-23113) Affect Siemens RUGGEDCOM APE1808 via Bundled Fortinet NGFW < V7.4.3 (SSA-832273)CRITICAL
- September 2026 Microsoft Patch Tuesday — Record 966+ Vulnerabilities with Two Actively Exploited Zero-Days (CVE-2026-81963, CVE-2026-85880) and Multiple Critical Wormable RCEsCRITICAL
- Microsoft September 2026 Patch Tuesday — 999 CVEs, 3 actively exploited zero-days (CVE-2026-85880, CVE-2026-81963, CVE-2026-85046)CRITICAL
- Microsoft August 2026 Patch Tuesday: 400 Flaws Fixed, Including Lazarus-Exploited Zero-Day CVE-2026-68820 (AFD.sys) and Two Publicly Disclosed Zero-Days (CVE-2026-62832 "LegacyHive", CVE-2026-72971)CRITICAL
- Redis Streams Shared-NACK Double-Free (CVE-2026-25243) & RedisBloom RESTORE/TDigest Heap Overflow (CVE-2026-25589) — Authenticated RCE, Public PoC, Patch BypassHIGH
- Microsoft's MDASH AI Scanning Harness Uncovers 16 Windows CVEs, Including Four Critical RCE Flaws in TCP/IP, IKEv2, Netlogon, and DNSCRITICAL
- PinTheft — Linux Kernel RDS Zerocopy FOLL_PIN Refcount Imbalance Chained With io_uring Fixed Buffers For Page-Cache Overwrite And Local Root (Public PoC, Arch Linux Default-Affected)HIGH
- CVE-2026-23918 — Apache HTTP Server mod_http2 Double Free Enabling Unauthenticated DoS and Possible RCECRITICAL
- CVE-2026-33824: Windows IKE Extensions Unauthenticated RCE via Double FreeCRITICAL
- CrackArmor — 9 Linux AppArmor Confused Deputy Vulnerabilities Enable Root Privilege Escalation and Container EscapeHIGH
Mitigations
- Architecture and Design: Choose a language that provides automatic memory management.
- Implementation: Ensure that each allocation is freed only once. After freeing a chunk, set the pointer to NULL to ensure the pointer cannot be freed again. In complicated error conditions, be sure that clean-up routines respect the state of allocation properly. If the language is object oriented, ensure that object destructors delete each chunk of memory only once.
- Implementation: Use a static analysis tool to find double free instances.
Source: MITRE CWE, potential mitigations.
Detection methods (MITRE CWE)
- Fuzzing (effectiveness: High): Fuzz testing (fuzzing) is a powerful technique for generating large numbers of diverse inputs - either randomly or algorithmically - and dynamically invoking the code with those inputs. Even with random inputs, it is often capable of generating unexpected results such as crashes, memory corruption, or resource consumption. Fuzzing effectively produces repeatable test cases that clearly indicate bugs, which helps developers to diagnose the issues.
- Automated Static Analysis (effectiveness: High): Automated static analysis, commonly referred to as Static Application Security Testing (SAST), can find some instances of this weakness by analyzing source code (or binary/compiled code) without having to execute it. Typically, this is done by building a model of data flow and control flow, then searching for potentially-vulnerable patterns that connect "sources" (origins of input) with "sinks" (destinations where the data interacts with external components, a lower layer such as the OS, etc.)
- Automated Dynamic Analysis (effectiveness: Moderate): Use tools that are integrated during compilation to insert runtime error-checking mechanisms related to memory safety errors, such as AddressSanitizer (ASan) for C/C++ [REF-1518].
Source: MITRE CWE, detection methods. Threadlinqs detection rules for the threats above are Blue tier and higher.