{"id":"ROOT-OS-DEBIAN-bullseye-CVE-2022-40090","summary":"CVE-2022-40090 in rootio-tiff - Patched by Root","details":"Root has patched CVE-2022-40090 in the rootio-tiff package for Root:Debian:bullseye. Multiple fixed versions available.","aliases":["CVE-2022-40090","ROOT-OS-DEBIAN-11-CVE-2022-40090"],"modified":"2026-02-25T09:00:26.052665Z","published":"2025-12-04T12:36:54Z","withdrawn":"2026-02-25T09:00:26.052665Z","database_specific":{"distro_version":"bullseye","distro":"debian","source":"Root"},"affected":[{"package":{"name":"rootio-tiff","ecosystem":"Root:Debian:bullseye","purl":"pkg:generic/root/rootio-tiff@4.2.0-1+deb11u5.root.io.9"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.2.0-1+deb11u6.root.io.4"},{"fixed":"4.2.0-1+deb11u5.root.io.5"},{"fixed":"4.2.0-1+deb11u5.root.io.6"},{"fixed":"4.2.0-1+deb11u5.root.io.7"},{"fixed":"4.2.0-1+deb11u5.root.io.8"},{"fixed":"4.2.0-1+deb11u5.root.io.9"}]}],"database_specific":{"all_fixed_versions":["4.2.0-1+deb11u6.root.io.4","4.2.0-1+deb11u5.root.io.5","4.2.0-1+deb11u5.root.io.6","4.2.0-1+deb11u5.root.io.7","4.2.0-1+deb11u5.root.io.8","4.2.0-1+deb11u5.root.io.9"],"root_patch_version":"root.io.9","root_patched":true,"source":"https://api.root.io/external/osv/ROOT-OS-DEBIAN-bullseye-CVE-2022-40090.json","total_fixed_versions":6,"upstream_version":"4.2.0-1+deb11u5"}}],"schema_version":"1.7.3"}