libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c. https://github.com/stephane/libmodbus/issues/683
Created libmodbus tracking bugs for this issue: Affects: epel-all [bug 2278753] Affects: fedora-all [bug 2278752]
There does not seem to be a resolution to this CVE upstream at this time. The POC is not entirely clear, they may be fuzzing a response to the test server; I've asked for clarification in the github issue.