See how root compares to other vendors in security performance
Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inffast.C.
This issue affects root.
The (1) proofserv, (2) xrdcp, (3) xrdpwdadmin, and (4) xrd scripts in ROOT 5.18/00 place a zero-length directory name in the LDLIBRARYPATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
Hi,
On Sun, May 24, 2026 at 10:07:07PM +0700, Manopakorn Kooharueangrong wrote: I am requesting that you coordinate a CVE assignment. It's been many years since you could request CVE assignment from this list. I guess this somehow got into the training of some popular LLMs, since we started getting this sort of requests again lately. == Disclosure ==
The fix is already public via PR #22377. I plan to publish this advisory once a CVE is assigned, or after 90 days from today if no CVE is assigned. You've just published this advisory to oss-security. We also started getting this sort of nonsense about delayed publication in postings to oss-security lately, which again must be the way some LLM is "confused". Please acknowledge receipt. Please disclose the specifics of your use of AI in your reports.
Alexander