Fedora has issued an advisory today (January 18): https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/thread/6JWWFGYQ3TPLXJZURXVSHGIGUMGDVZV5/ The bundled dcraw code is updated to 9.28 to include the latest fixes (including security bugs) from there. The update was in this commit: https://src.fedoraproject.org/rpms/ufraw/c/7f1623ebd61f2ece75441243e3af04f4e9970a98?branch=master
Fixed by David Geiger in ufraw-0.22-18.mga8.
Resolution: (none) => FIXEDAssignee: bugsquad => geiger.david68210Status: NEW => RESOLVED