fix CVE-2022-44566 CVE-2023-22794 (cherry picked from commit ead83c6d23c77103756b10a0ec6501a8a5601c52)