See https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2016-5131 : Use-after-free vulnerability in libxml2 through 2.9.4, as used in Google Chrome before 52.0.2743.82, allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the XPointer range-to function.
The patch for this is in master, pyro and morty - can we mark this resolved?
pyro: 96ef568f75dded56a2123b63dcc8b443f796afe0 640bd2b98ff33e49b42f1087650ebe20d92259a4 morty: 68b0f3a0bf8dfdf49be4aed1745a7f50662c555d 1e284447b9bf42e1fd6080f5a50fe01c8267a4e6