There is an integer overflow in Shannon Baseband leading to a heap buffer overflow when reassembling IPv4 fragments. According to the debug strings, this corresponding functionality is implemented in SmdtIp4Rx::ProcessFragments function and its callees.
85296d153a53a5ed603bc0ad519a9d3336041170d6909013ceb81a85f4d1624b