The vulnerability exists due to missing boundary constraints inside the SMB/CIFS protocol inspection pipeline. Malformed file-sharing transaction packets with mismatched header lengths allow incoming data to spill out of designated network buffers, risking localized memory corruption.