CWE-562Base

Return of Stack Variable Address

Draft in the CWE catalog · 6 CVEs mapped

6
CVEs mapped
7.3
Median CVSS
What it is

A function returns the address of a stack variable, which will cause unintended program behavior, typically in the form of a crash.

Recent examples
4.0cvss
CVE-2026-34553

iccDEV: DoS in CIccCLUT::Iterate() & CIccMBB::Describe()

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Prior to version 2.3.1.6, there is a defect in LUT dump/iteration logic affecting CIccCLUT::Iterate() and output produced by CIccMBB::Describe() (via CLUT dumping). This issue has been patched in version 2.3.1.6.

MEDIUMno explanation yet
0%
epss
5.4cvss
CVE-2026-3591

A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass

A use-after-return vulnerability exists in the `named` server when handling DNS queries signed with SIG(0). Using a specially-crafted DNS request, an attacker may be able to cause an ACL to improperly (mis)match an IP address. In a default-allow ACL (denying only specific IP addresses), this may lead to unauthorized access. Default-deny ACLs should fail-secure. This issue affects BIND 9 versions 9.20.0 through 9.20.20, 9.21.0 through 9.21.19, and 9.20.9-S1 through 9.20.20-S1. BIND 9 versions 9.18.0 through 9.18.46 and 9.18.11-S1 through 9.18.46-S1 are NOT affected.

MEDIUMno explanation yet
0%
epss
8.4cvss
CVE-2024-33045

Return of Stack Variable Address in Buses

Memory corruption when BTFM client sends new messages over Slimbus to ADSP.

HIGHno explanation yet
0%
epss
The record
Technical detail
CWE ID
CWE-562
Abstraction
Base
Structure
Simple
Status
Draft
References (1)