fix CVE-2022-23648 Signed-off-by: Vanient <xiadanni1@huawei.com> (cherry picked from commit 1c20efac8910ccd8180a341eca90db76442b8fef)