Fix other occurrences of same bounds check issue

Security impact is the same: not triggerrable remotely except in very specific
use cases

backport of 4dc9b39
2 files changed