CVE-2020-36404 (https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=22371): Keystone Engine 0.9.2 has an invalid free in llvm_ks::SmallVectorImpl<llvm_ks::MCFixup>::~SmallVectorImpl. CVE-2020-36405 (https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=22850): Keystone Engine 0.9.2 has a use-after-free in llvm_ks::X86Operand::getToken. Need to investigate closer whether these are fixed, the oss-fuzz marked them as fixed by the marked commits didn't seem relevant.
Package list is empty or all packages have requested keywords.
upstream bug report: https://github.com/keystone-engine/keystone/issues/516
I've reported the incorrect fix report to upstream: https://github.com/google/oss-fuzz/issues/8283