The vulnerability exists due to a use-after-free (UAF) condition inside the TCP stream reassembly layer. When a connection undergoes abrupt termination sequences (such as an interleaving flood of RST and FIN packets), the flow tracking engine frees network payload metadata objects prematurely while active parsing references are still attached.