CVEbaza.plSłownik CWECWE-413
Common Weakness Enumeration

CWE-413

Improper Resource Locking

Kategoria: BaseCVE: 15
Opis

Produkt nie blokuje lub nieprawidłowo blokuje zasób, gdy wymaga wyłącznego dostępu do tego zasobu. Może to prowadzić do wyścigu danych i niespójności stanu aplikacji.

Description (EN)

The product does not lock or does not correctly lock a resource when the product must have exclusive access to the resource.

Podatności CVE z CWE-413 (15)
9.3
CVSS
CRITICAL
CVE-2025-3450

Podatność typu Improper Resource Locking w komponencie SDM systemu B&R Automation Runtime umożliwia nieuwierzytelnionemu atakującemu zdalnie usunięcie danych i wywołanie stanu odmowy usługi (DoS). Krytyczna ocena CVSS 9.3 wynika z braku wymagań uwierzytelnienia oraz szerokiego wpływu na integralność i dostępność systemu.

pub. 2025-10-07
8.7
CVSS
HIGH
CVE-2026-32748

Squid is a caching proxy for the Web. Prior to version 7.5, due to premature release of resource during expected lifetime and heap Use-After-Free bugs, Squid is vulnerable to Denial of Service when handling ICP traffic. This problem allows a remote attacker to perform a reliable and repeatable Denial of Service attack against the Squid service using ICP protocol. This attack is limited to Squid deployments that explicitly enable ICP support (i.e. configure non-zero `icp_port`). This problem _cannot_ be mitigated by denying ICP queries using `icp_access` rules. This bug is fixed in Squid version 7.5.

pub. 2026-03-26
8.6
CVSS
HIGH
CVE-2023-28649

The Hub in the Snap One OvrC cloud platform is a device used to centralize and manage nested devices connected to it. A vulnerability exists in which an attacker could impersonate a hub and send device requests to claim already claimed devices. The OvrC cloud platform receives the requests but does not validate if the found devices are already managed by another user.

pub. 2023-05-22
8.6
CVSS
HIGH
CVE-2022-20678

A vulnerability in the AppNav-XE feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause an affected device to reload, resulting in a denial of service (DoS) condition. This vulnerability is due to the incorrect handling of certain TCP segments. An attacker could exploit this vulnerability by sending a stream of crafted TCP traffic at a high rate through an interface of an affected device. That interface would need to have AppNav interception enabled. A successful exploit could allow the attacker to cause the device to reload.

pub. 2022-04-15
8.3
CVSS
HIGH
CVE-2019-17102

An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version 2.0.1.91. The API method `/api/update_setup` does not perform firmware signature checks atomically, leading to an exploitable race condition (TOCTTOU) that allows arbitrary execution of system commands. This issue affects: Bitdefender Bitdefender BOX 2 versions prior to 2.1.47.36.

pub. 2020-01-27
7.8
CVSS
HIGH
CVE-2019-8998

An information disclosure vulnerability leading to a potential local escalation of privilege in the procfs service (the /proc filesystem) of BlackBerry QNX Software Development Platform version(s) 6.5.0 SP1 and earlier could allow an attacker to potentially gain unauthorized access to a chosen process address space.

pub. 2019-07-12
7.7
CVSS
HIGH
CVE-2022-49737

In X.Org X server 20.11 through 21.1.16, when a client application uses easystroke for mouse gestures, the main thread modifies various data structures used by the input thread without acquiring a lock, aka a race condition. In particular, AttachDevice in dix/devices.c does not acquire an input lock.

pub. 2025-03-16
7.5
CVSS
HIGH
CVE-2022-24946

Improper Resource Locking vulnerability in Mitsubishi Electric MELSEC iQ-R Series R12CCPU-V firmware versions "16" and prior, Mitsubishi Electric MELSEC-Q Series Q03UDECPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/10/13/20/26/50/100UDEHCPU the first 5 digits of serial No. "24061" and prior, Mitsubishi Electric MELSEC-Q Series Q03/04/06/13/26UDVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q04/06/13/26UDPVCPU the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-Q Series Q12DCCPU-V all versions, Mitsubishi Electric MELSEC-Q Series Q24DHCCPU-V(G) all versions, Mitsubishi Electric MELSEC-Q Series Q24/26DHCCPU-LS all versions, Mitsubishi Electric MELSEC-L series L02/06/26CPU(-P) the first 5 digits of serial number "24051" and prior, Mitsubishi Electric MELSEC-L series L26CPU-(P)BT the first 5 digits of serial number "24051" and prior and Mitsubishi Electric MELIPC Series MI5122-VW firmware versions "05" and prior allows a remote unauthenticated attacker to cause a denial of service (DoS) condition in Ethernet communications by sending specially crafted packets. A system reset of the products is required for recovery.

pub. 2022-06-15
7.3
CVSS
HIGH
CVE-2025-0003

Inadequate lock protection within Xilinx Run time may allow a local attacker to trigger a Use-After-Free condition potentially resulting in loss of confidentiality or availability

pub. 2025-11-24
6.7
CVSS
MEDIUM
CVE-2023-33951

A race condition vulnerability was found in the vmwgfx driver in the Linux kernel. The flaw exists within the handling of GEM objects. The issue results from improper locking when performing operations on an object. This flaw allows a local privileged user to disclose information in the context of the kernel.

pub. 2023-07-24
6.0
CVSS
MEDIUM
CVE-2025-69198

Pterodactyl to bezpłatny, otwartoźródłowy panel zarządzania serwerami gier. Aplikacja implementuje limity szybkości dla całkowitej liczby zasobów (np. baz danych, przydziałów portów czy backupów) dostępnych dla pojedynczego serwera, jednak w wersjach przed 1.12.0 złośliwy użytkownik może wysłać ogromną ilość równoczesnych żądań tworzących więcej zasobów niż dozwolone, ponieważ walidacja odbywa się na wczesnym etapie cyklu żądania bez blokowania zasobu podczas przetwarzania. W rezultacie serwer może utworzyć więcej baz danych, przydziałów czy backupów niż skonfigurowano, umożliwiając złośliwemu użytkownikowi odmowę dostępu do zasobów innym użytkownikom i nadmierne zużycie przydzielonych alokacji. Wersja 1.12.0 naprawia ten problem.

pub. 2026-01-19
5.9
CVSS
MEDIUM
CVE-2023-32253

A flaw was found in the Linux kernel's ksmbd component. A deadlock is triggered by sending multiple concurrent session setup requests, possibly leading to a denial of service.

pub. 2025-08-02
5.5
CVSS
MEDIUM
CVE-2023-2430

A vulnerability was found due to missing lock for IOPOLL flaw in io_cqring_event_overflow() in io_uring.c in Linux Kernel. This flaw allows a local attacker with user privilege to trigger a Denial of Service threat.

pub. 2023-07-23
4.6
CVSS
MEDIUM
CVE-2026-44608

NLnet Labs Unbound w wersjach od 1.14.0 do 1.25.0 zawiera podatność locking inconsistency — przy spełnieniu określonych warunków (multi-threading, RPZ XFR reload, strefa RPZ z triggerami 'rpz-nsip'/'rpz-nsdname') może dojść do heap use-after-free i awarii. Podatność można wykorzystać, gdy serwer Unbound działa w trybie multi-threaded ze strefą RPZ zawierającą triggery 'rpz-nsip'/'rpz-nsdname' oraz wykonywane jest XFR dla tej strefy. Jeśli XFR zachodzi w tym samym czasie, gdy inny wątek odczytuje strefę RPZ, wątek odczytujący może nie utrzymywać blokady wystarczająco długo, a wątek aplikujący XFR uwolni obiekty, które czytnik zamierza przetwarzać, powodując use-after-free. Unbound 1.25.1 zawiera poprawkę do kodu blokady.

pub. 2026-05-20
4.4
CVSS
MEDIUM
CVE-2023-2269

A denial of service problem was found, due to a possible recursive locking scenario, resulting in a deadlock in table_clear in drivers/md/dm-ioctl.c in the Linux Kernel Device Mapper-Multipathing sub-component.

pub. 2023-04-25
Informacje
ID: CWE-413
Typ: Base
Podatności: 15
MITRE CWE ↗
← Słownik CWE