glibc timezone/zic.c relname(): integer overflow in allocation sizes can lead to heap OOB writes
libiberty: integer overflow in vasprintf size calculation can lead to heap buffer overflow