fig2dev 3.2.7b contains a stack buffer overflow in the bezier_spline function in genepic.c. Reference: https://sourceforge.net/p/mcj/tickets/65/
After analysis and testing with provided PoC, RHEL 8.4.0 - 9.0.0 is affected by this flaw. The patch to fix this flaw is: https://sourceforge.net/p/mcj/fig2dev/ci/e3cee2576438f47a3b8678c6960472e625f8f7d7/ and can be easily backported to fix the existing flaws.
Analysis did not show any sign of being able to achieve code execution with this flaw. The flaw present caused a denial of service to the program affecting availability, but with no found effects on Integrity or Confidentiality of data. As such the CVSS score should be 5.5/CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H