CVE-2023-2961 (https://bugzilla.redhat.com/show_bug.cgi?id=2210768): A segmentation fault flaw was found in the Advancecomp package. This may lead to decreased availability. The sole reference is quite useless, no reference to upstream report or fixed version.
Do I understand correctly that what we've basically got is a report that there is some bug somewhere but no clue what it's about and when it's going to be fixed?
According to the redhat bug this is fixed in advancecomp 2.5, and its release notes mention: "* Fix segmentation fault on invalid MNG size".