The vulnerability exists due to an integer overflow condition inside the TLS certificate parsing engine. An unauthenticated remote attacker can send an excessively long or malformed Extensions field within a Client Hello packet, forcing an incorrect memory allocation size that results in a process-terminating Denial of Service (DoS).