For reference, crossposting: I pushed 00c67375b17f4a4cfad53399d1918f2e7eba2c7d to core-updates. Your patch. Thank you for it. Let's watch for upstream zstd fix also. I pushed 9feef62b73e284e106717a386624d6da90750a3d to master. Ubuntu released a patch in the mean time, so while we couldnt make such patch in a timely manner because the backport was non-trivial and security-sensitive also didnt want to risk failing to fix the flaw because I don't have much expertise on it, Ubuntu now has done that work and we can just use it. Léo