The product uses a reference count to manage a resource, but it does not update or incorrectly updates the reference count.
Volume of CVEs assigned to CWE-911 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
16 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-46316CRITICAL In the Linux kernel, the following vulnerability has been resolved:
KVM: arm64: vgic-its: Drop the translation cache reference only for the erased entry
vgic_its_invalidate_cache | Jun 9, 2026 | 9.3 | 43 | NO | NO |
CVE-2026-52943HIGH In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: fix missing zerocopy reference in pskb_carve helpers
pskb_carve_inside_header() and pskb_carve_in | Jun 24, 2026 | 7.8 | 36 | NO | NO |
CVE-2024-43102CRITICAL Concurrent removals of certain anonymous shared memory mappings by using the UMTX_SHM_DESTROY sub-request of UMTX_OP_SHM can lead to decreasing the reference count of the object re | Sep 5, 2024 | 10.0 | 31 | NO | NO |
CVE-2026-46099HIGH In the Linux kernel, the following vulnerability has been resolved:
net: ipv6: fix NOREF dst use in seg6 and rpl lwtunnels
seg6_input_core() and rpl_input() call ip6_route_input( | May 27, 2026 | 8.1 | 30 | NO | NO |
CVE-2022-29581HIGH Improper Update of Reference Count vulnerability in net/sched of Linux Kernel allows local attacker to cause privilege escalation to root. This issue affects: Linux Kernel versions | May 17, 2022 | 7.8 | 27 | NO | NO |
CVE-2026-42534MEDIUM NLnet Labs Unbound up to and including version 1.25.0 has a vulnerability in the jostle logic that could defeat its purpose and degrade resolution performance. Retransmits of the s | May 20, 2026 | 5.3 | 26 | NO | NO |
CVE-2022-37012HIGH This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server 1.7.6-537. Authentication | Mar 29, 2023 | 7.5 | 24 | NO | NO |
CVE-2023-22394HIGH An Improper Handling of Unexpected Data Type vulnerability in the handling of SIP calls in Juniper Networks Junos OS on SRX Series and MX Series platforms allows an attacker to cau | Jan 13, 2023 | 7.5 | 24 | NO | NO |
CVE-2022-22195HIGH An Improper Update of Reference Count vulnerability in the kernel of Juniper Networks Junos OS Evolved allows an unauthenticated, network-based attacker to trigger a counter overfl | Apr 14, 2022 | 7.5 | 24 | NO | NO |
CVE-2024-46972HIGH Software installed and run as a non-privileged user may conduct improper GPU system calls to trigger use-after-free kernel exceptions. | Dec 28, 2024 | 7.8 | 22 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.