A flaw was found in libebml before 1.4.2. A heap overflow bug exists in the implementation of EbmlString::ReadData and EbmlUnicodeString::ReadData in libebml.
https://security.gentoo.org/glsa/202208-21
https://lists.debian.org/debian-lts-announce/2021/04/msg00016.html