fixes CVEs 2021-3570 and 2021-3571 (cherry picked from commit 4d881f91494fed25350ec77239a7d06ff08fa91a)