Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89388.json"