Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20260524165449.GA14609@openwall.com>
Date: Sun, 24 May 2026 18:54:49 +0200
From: Solar Designer <solar@...nwall.com>
To: Manopakorn Kooharueangrong <manopakorn.sec@...il.com>
Cc: oss-security@...ts.openwall.com
Subject: Re: root-project/root: Heap buffer overflow in TKey::Streamer / TBasket::ReadBasketBuffers

Hi,

On Sun, May 24, 2026 at 10:07:07PM +0700, Manopakorn Kooharueangrong wrote:
> I am requesting that you coordinate a CVE assignment.

It's been many years since you could request CVE assignment from this
list.  I guess this somehow got into the training of some popular LLMs,
since we started getting this sort of requests again lately.

> == Disclosure ==
> 
> The fix is already public via PR #22377. I plan to publish this advisory
> once a CVE is assigned, or after 90 days from today if no CVE is assigned.

You've just published this advisory to oss-security.  We also started
getting this sort of nonsense about delayed publication in postings to
oss-security lately, which again must be the way some LLM is "confused".

> Please acknowledge receipt.

Please disclose the specifics of your use of AI in your reports.

Alexander

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.