We cannot simply treat a pointer to struct oin6_aliasreq as a pointer to
struct in6_aliasreq: the latter is larger. In particular, the store to
ifra->ifra_vhid is out of bounds.
Since OSIOCAIFADDR_IN6 does not need to copy data back out, it can
simply use a struct in6_ifaliasreq on the stack.
Reported by: Andrew <xxx.sys@protonmail.com>