https://seclists.org/oss-sec/2026/q2/681: root-project/root: Heap buffer overflow in TKey::Stamer / TBasket::adBasketBuffers
Published May 24, 2026
·Updated
Affected Software
1 affected component
ROOT ROOT
Frequently Asked Questions
1
Is a fix publicly available?
Yes. The report states that the fix is already public in PR #22377.
2
Does the report identify affected versions, attack prerequisites, or temporary mitigations?
No. It does not provide affected version information, exploitation conditions, configuration scope, or mitigations for systems that cannot apply the fix.