The use-after-free in parse_lease_state() Missing check NameOffset in parse_lease_state() makes create_context object can access invalid memory.
Created kernel tracking bugs for this issue: Affects: fedora-all [bug 2154180]