cfg_tilde_expand in confuse.c in libConfuse 3.3 has a heap-based buffer over-read. https://github.com/libconfuse/libconfuse/issues/163
Updates in flight for Fedora all and EPEL 8 and 9.
Created libconfuse tracking bugs for this issue: Affects: epel-all [bug 2126403] Affects: fedora-all [bug 2126404]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.