From ${URL} : Fix more NULL pointer derefs in xpointer.c Found with afl-fuzz. @maintainer(s): after the bump, in case we need to stabilize the package, please let us know if it is ready for the stabilization or not.
Patch not present in 2.9.4 release. Will need to backport or await upstream inclusion.
(In reply to Aaron Bauman from comment #1) > Patch not present in 2.9.4 release. Will need to backport or await upstream > inclusion. My apologies, but backport is the wrong terminology. Patch not present in 2.9.4. Will require addition in tree or await upstream inclusion.
This issue was resolved and addressed in GLSA 201701-37 at https://security.gentoo.org/glsa/201701-37 by GLSA coordinator Thomas Deutschmann (whissi).