The TCP-over-UDP ICMP callback receives ip6c_m as a borrowed chain owned
by icmp6_notify_error. It used m_pulldown() to obtain a contiguous UDP
header even though that API frees the complete chain when the requested
range is unavailable. The callback could then return without
propagating the lost ownership, leaving raw ICMP delivery to read and
free a stale head.
Validate that the complete UDP header was quoted, copy it through the
chain with m_copydata(), and temporarily advance the parser offset
instead of consuming bytes from the caller-owned packet.
A remote sender can reach the old path when TCP UDP tunneling is enabled
by quoting the configured local UDP source port in an ICMPv6 error and
including only four through seven UDP-header bytes.