See how root compares to other vendors in security performance
Hi,
On Sun, May 24, 2026 at 10:07:07PM +0700, Manopakorn Kooharueangrong wrote: I am requesting that you coordinate a CVE assignment. It's been many years since you could request CVE assignment from this list. I guess this somehow got into the training of some popular LLMs, since we started getting this sort of requests again lately. == Disclosure ==
The fix is already public via PR #22377. I plan to publish this advisory once a CVE is assigned, or after 90 days from today if no CVE is assigned. You've just published this advisory to oss-security. We also started getting this sort of nonsense about delayed publication in postings to oss-security lately, which again must be the way some LLM is "confused". Please acknowledge receipt. Please disclose the specifics of your use of AI in your reports.
Alexander
Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C.
This issue affects root.
The (1) proofserv, (2) xrdcp, (3) xrdpwdadmin, and (4) xrd scripts in ROOT 5.18/00 place a zero-length directory name in the LDLIBRARYPATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.