Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Although I see no evidence that this is an issue, I do not know how it might be triggered, so I cannot test it. I asked a similar question about gputils and have not gotten any response. I also do not know what is meant by "starting the update process" as this package looks to be updated to F44. Note that sdcc and gputils use the same code.