mDNS string-cache lookup matches on slot size, so a peer name aliases a shorter one and the response encoder writes past the packet (CVE-2026-102715) | HOL Guard CVE