oss-sec mailing list archives
Re: root-project/root: Heap buffer overflow in TKey::Streamer / TBasket::ReadBasketBuffers
From: Solar Designer <solar () openwall com>
Date: Sun, 24 May 2026 18:54:49 +0200
Hi, On Sun, May 24, 2026 at 10:07:07PM +0700, Manopakorn Kooharueangrong wrote:
I am requesting that you coordinate a CVE assignment.
It's been many years since you could request CVE assignment from this list. I guess this somehow got into the training of some popular LLMs, since we started getting this sort of requests again lately.
== Disclosure == The fix is already public via PR #22377. I plan to publish this advisory once a CVE is assigned, or after 90 days from today if no CVE is assigned.
You've just published this advisory to oss-security. We also started getting this sort of nonsense about delayed publication in postings to oss-security lately, which again must be the way some LLM is "confused".
Please acknowledge receipt.
Please disclose the specifics of your use of AI in your reports. Alexander
Current thread:
- root-project/root: Heap buffer overflow in TKey::Streamer / TBasket::ReadBasketBuffers Manopakorn Kooharueangrong (May 24)
- Re: root-project/root: Heap buffer overflow in TKey::Streamer / TBasket::ReadBasketBuffers Solar Designer (May 24)
- Re: root-project/root: Heap buffer overflow in TKey::Streamer / TBasket::ReadBasketBuffers Matt Christie (May 24)
- Re: root-project/root: Heap buffer overflow in TKey::Streamer / TBasket::ReadBasketBuffers Solar Designer (May 24)
