CWE-775: Missing Release of File Descriptor or Handle after Effective Lifetime
The product does not release a file descriptor or handle after its effective lifetime has ended, i.e., after the file descriptor/handle is no longer needed.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2019-25557 — TwistedBrush Pro Studio 24.06 Denial of Service via srp File
- CVE-2026-78408 — Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
- CVE-2025-53476 — A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5c
- CVE-2026-45287 — OpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse
- CVE-2025-13751 — Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a loc
Recently published
- CVE-2026-78408 — Util-linux: util-linux: nsenter --join-cgroup leaks root cgroup migration authority
- CVE-2026-45287 — OpenTelemetry-Go's Schema ParseFile leaks file descriptors on each parse
- CVE-2019-25557 — TwistedBrush Pro Studio 24.06 Denial of Service via srp File
- CVE-2025-13751 — Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a loc
- CVE-2025-53476 — A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5c