Description: out-of-bound read in memcpy_fromiovecend() References: https://bugzilla.redhat.com/show_bug.cgi?id=1661503 Notes: carnil> Not much details provided in RedHat Bugzilla #1661503 but said carnil> that the issue is indirectly fixed upstream by UFO removal, and carnil> the buggy memcpy_fromiovecend() (and related functions) are carnil> fixed by upstream commit carnil> 21226abb4e9f14d88238964d89b279e461ddc30c (4.0-rc1) Bugs: upstream: released (3.17-rc1) [06ebb06d49486676272a3c030bfeef4bd969a8e6] 4.19-upstream-stable: N/A "Fixed before branch point" 4.9-upstream-stable: N/A "Fixed before branch point" 3.16-upstream-stable: released (3.16.1) [874c613a476d6a283ce418290c4472a07dadadf6] sid: released (3.16.2-1) 4.9-stretch-security: N/A "Fixed before branch point" 3.16-jessie-security: N/A "Fixed before branch point"