fixes CVE-2021-21705 and CVE-2021-21704 (cherry picked from commit cf9fe3942e90eb6f97cfb69daa391b83f9868883)