Fix two possible out-of-bounds accesses

Merged Peter Hutterer requested to merge whot/xserver:server-21.1-branch into server-21.1-branch

The second one is CVE-2023-0494 from !1063 (merged)

Merge request reports