CWE-562: Return of Stack Variable Address
A function returns the address of a stack variable, which will cause unintended program behavior, typically in the form of a crash.
6 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-33045 — Return of Stack Variable Address in Buses
- CVE-2024-4418 — Libvirt: stack use-after-free in virnetclientioeventloop()
- CVE-2026-3591 — A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
- CVE-2026-34553 — iccDEV: DoS in CIccCLUT::Iterate() & CIccMBB::Describe()
Recently published
- CVE-2026-34553 — iccDEV: DoS in CIccCLUT::Iterate() & CIccMBB::Describe()
- CVE-2026-3591 — A stack use-after-return flaw in SIG(0) handling code may enable ACL bypass
- CVE-2024-33045 — Return of Stack Variable Address in Buses
- CVE-2024-4418 — Libvirt: stack use-after-free in virnetclientioeventloop()