The vulnerability is caused by improper check for check if RDLENGTH does not overflow the buffer in response from DNS server.
{ "urgency": "not yet assigned" }