We convert a string like "W32:vendor/device" into "I:vendor;I:device",
where the output is longer than the input, but only allocate space equal
to the length of the input, leading to a buffer overflow.
Instead use open_memstream so we get a safe dynamically-grown buffer.
Found by: CHERI
Obtained from: CheriBSD
I see this and wonder how the VF driver even worked upstream. Is there something that I'm missing here?