systemd is vulnerable to denial of service. The vulnerability exists due to the on_stream_io()
function and dns_stream_complete()
function in resolved-dns-stream.c
does not properly increment the reference counting for the DnsStream object, allowing an attacker to cause a system crash through the dereference in the DNSStream object, causing the user-after-free when the reference is still used later.