patch: apply upstream cve fixes