CWE-911Base

Improper Update of Reference Count

Incomplete in the CWE catalog · 16 CVEs mapped

16
CVEs mapped
7.5
Median CVSS
What it is

The product uses a reference count to manage a resource, but it does not update or incorrectly updates the reference count.

Recent examples
5.9cvss
CVE-2026-77587

CVE-2026-77587 - MEDIUM Severity Vulnerability

Tor before 0.4.9.11 is prone to a use-after-free (and potential double free) of a conflux object when a recovery leg revives a conflux set whose last linked leg has already been closed. A malicious exit node could use this to crash a client. This is TROVE-2026-026.

MEDIUMno explanation yet
0%
epss
8.8cvss
CVE-2026-49419

CVE-2026-49419 - HIGH Severity Vulnerability

When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's current prison before looking up the jail descriptor. If the descriptor lookup failed, error-handling paths released the same reference a second time. An unprivileged local user can trigger a prison reference count underflow, which may cause the prison structure to be freed while still in use. When this is done on the jail host, the bug will generally result in an immediate panic. However, if the user is running in a jail, then it may be possible to exploit the bug to elevate privileges.

HIGHno explanation yet
0%
epss
2.3cvss
CVE-2026-19380

CVE-2026-19380 - LOW Severity Vulnerability

A vulnerability was identified in Mullvad wireguard.sys 0.10.1. The affected element is the function AdapterState of the component IOCTL Handler. Such manipulation leads to improper update of reference count. Local access is required to approach this attack. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure.

LOWno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-911
Abstraction
Base
Structure
Simple
Status
Incomplete
References (1)