with_capacity/Vec sizing from a multiplication of untrusted values can overflow.
Use checked_mul and validate sizes before allocating from untrusted input.