[ Reason ]
Backport of non-DSA CVE-2026-14191.
[ Impact ]
Users are vulnerable to out-of-heap writes.
[ Tests ]
Only compile-tested and extracted one rar5 file.
[ Risks ]
Bounds checks for two variables are pretty trivial.
[ Checklist ]
[x] *all* changes are documented in the d/changelog
[x] I reviewed all changes and I approve them
[x] attach debdiff against the package in (old)stable
[x] the issue is verified as fixed in unstable
[ Changes ]
One patch backporting the changes in recvol5.cpp of v7.2.7 to 7.1.8.
[ Other info ]
Non-maintainer request.