CVE-2025-31344 and cleanup

This backports the proposed patch for CVE-2025-31344, builds from git as a transparent source, and cleans up a few lines. The check() function prevents the package from building even in its current unmodified state, so it's disabled for now.

https://seclists.org/oss-sec/2025/q2/21

https://seclists.org/oss-sec/2025/q2/25

Merge request reports

Loading