The CVE was backported and fixed in 2.7-r3. ref #11914 This reverts commit bda7554d.
mentioned in issue #11914 (closed)