The vlserver in OpenAFS before 1.6.13 allows remote authenticated users to cause a denial of service (out-of-bounds read and crash) via a crafted regular expression in a VL_ListAttributesN2 RPC.
https://www.openafs.org/dl/openafs/1.6.13/RELNOTES-1.6.13
https://lists.openafs.org/pipermail/openafs-announce/2015/000486.html
http://www.openafs.org/pages/security/OPENAFS-SA-2015-006.txt