listtransactions adds count and skip as int. Each one is checked to be non-negative, but their sum can still go past INT_MAX:
bitcoin-cli -regtest listtransactions "*" 2147483647 1
On master this crashes the node. The overflowed sum is negative, so the loop stops after the first entry. The clamp after the loop overflows the same way and doesn't fix nCount, so push_backV gets an iterator range about 2^31 elements before rend(). UBSan reports signed integer overflow: 1 + 2147483647 at transactions.cpp:584, and ASan then reports a BUS error in UniValue::push_backV.
This does both additions in int64_t. The functional test calls listtransactions with count + skip above INT_MAX and checks the results match a normal-sized request. It times out on master (the node crashes) and passes with the fix. I also ran it on an ASan/UBSan build.
listrawtransactions counts differently and isn't affected.