|
|
Message-ID: <20260524165449.GA14609@openwall.com> Date: Sun, 24 May 2026 18:54:49 +0200 From: Solar Designer <solar@...nwall.com> To: Manopakorn Kooharueangrong <manopakorn.sec@...il.com> Cc: oss-security@...ts.openwall.com Subject: Re: root-project/root: Heap buffer overflow in TKey::Streamer / TBasket::ReadBasketBuffers Hi, On Sun, May 24, 2026 at 10:07:07PM +0700, Manopakorn Kooharueangrong wrote: > I am requesting that you coordinate a CVE assignment. It's been many years since you could request CVE assignment from this list. I guess this somehow got into the training of some popular LLMs, since we started getting this sort of requests again lately. > == Disclosure == > > The fix is already public via PR #22377. I plan to publish this advisory > once a CVE is assigned, or after 90 days from today if no CVE is assigned. You've just published this advisory to oss-security. We also started getting this sort of nonsense about delayed publication in postings to oss-security lately, which again must be the way some LLM is "confused". > Please acknowledge receipt. Please disclose the specifics of your use of AI in your reports. Alexander
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.