patch for CVE-2021-29505

Taken from upstream commit, could you review it, please?

If it's okay, I'll prepare for it for buster-security, then.

Merge request reports

Loading