CVE-2026-24812
CVE-2026-24812
9.3
CriticalPublished:
Last updated:
Source:cve_disclosure@tech.gov.sg
Deferred
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Network
- Attack Complexity
- Low
- Attack Requirements
- None
- Privileges Required
- None
- User Interaction
- None
- Confidentiality (Vulnerable)
- Low
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- Low
- Integrity (Subsequent)
- High
- Availability (Subsequent)
- High
Description
Vulnerability in root-project root (builtins/zlib modules). This vulnerability is associated with program files inftrees.C. This issue affects root: through 6.36.00-rc1.
References
cve_disclosure@tech.gov.sg
https://github.com/root-project/root/pull/18527af854a3a-2127-422b-91ae-364da2661108
https://root.cern/blog/recent-common-vulnerabilities-when-does-ROOT-need-to-be-updated/