Mercurial before version 4.6.1 is vulnerable undefined behaviour due to integer overflows in mpatch.c:discard(). Upstream Changelog: https://www.mercurial-scm.org/wiki/WhatsNew#Mercurial_4.6.1_.282018-06-06.29 Upstream Patch: https://www.mercurial-scm.org/repo/hg/rev/7f22ef3c0ee7
Created mercurial tracking bugs for this issue: Affects: fedora-all [bug 1594088]