ncsi.c in libslirp through 4.3.1 has a buffer over-read because it tries to read a certain amount of header data even if that exceeds the total packet length.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2020-29129.json"