In GnuPG before 2.5.17, a long signature packet length causes parse_signature to return success with sig->data[] set to a NULL value, leading to a denial of service (application crash).
This does not affect any RHEL nor Fedora versions. This bug was introduced in https://dev.gnupg.org/rG36dbca3e6944d13e75e96eace634e58a7d7e201d which is only in the GnuPG 2.5.x versions per https://dev.gnupg.org/T8049 Please, adjust accordingly. I will close the Fedora trackers.