https://bugs.winehq.org/show_bug.cgi?id=39040
--- Comment #3 from Sebastian Lackner sebastian@fds-team.de --- Confirming. I would guess it has to do with a missing validation of loadcfg->Size. An additional check like loadcfg_size == loadcfg->Size seems to fix it, but difficult to say if its correct. I fear sooner or later we'll need test for those security cookies. :/