-Infinity
0

Vendor Risk Score

See how root compares to other vendors in security performance

View Risk Score →
Severity
9.8
EPSS
0.07%
Input Validation, Buffer Overflow
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:L/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:D/RE:M/U:Amber

Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C.

This issue affects root.

First published (updated )
Severity
6.9
AV:L/AC:M/Au:N/C:C/I:C/A:C

The (1) proofserv, (2) xrdcp, (3) xrdpwdadmin, and (4) xrd scripts in ROOT 5.18/00 place a zero-length directory name in the LDLIBRARYPATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.

First published (updated )

Hi,

On Sun, May 24, 2026 at 10:07:07PM +0700, Manopakorn Kooharueangrong wrote: I am requesting that you coordinate a CVE assignment. It's been many years since you could request CVE assignment from this list. I guess this somehow got into the training of some popular LLMs, since we started getting this sort of requests again lately. == Disclosure ==

The fix is already public via PR #22377. I plan to publish this advisory once a CVE is assigned, or after 90 days from today if no CVE is assigned. You've just published this advisory to oss-security. We also started getting this sort of nonsense about delayed publication in postings to oss-security lately, which again must be the way some LLM is "confused". Please acknowledge receipt. Please disclose the specifics of your use of AI in your reports.

Alexander

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203