Analysis creates new stack variable despite the offset belongs to a structure on the stack / Ghost stack variable not in the variable list

Open
#6,787 3 comments 0 reactions 1 assignee View on GitHub

@rssor is already working on this.

Since Jun 11, 2025.

Assessment

This issue has not been assessed yet.

Description

Component: Core Effort: Medium Impact: Medium Regression

We can see that analysis creates var_210 which appears to be not otherwise initialized before its usage.

Image

lppe is at ebp-0x230, and ebp-0x20c is being var_210:

Image

However, if we look at the stack, we can see it is actually the szExeFile field of struct PROCESSENTRY32W lppe:

Image

Binary: proud wizard dances cheerfully (malware sample, zip passwd infected)

Dominant language
C++
Stars
1.3k
Forks
298
Avg merge
5d 5h
Merged PRs (30d)
19

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

More from Vector35/binaryninja-api

All issues in Vector35/binaryninja-api

Similar issues

More C++ issues

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.