MSRC compact vulnerability detail

CVE-2026-28364 · In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.

No description was published by MSRC.

Severity
n/a
Impact
n/a
CVSS
7.9 base · 7.9 temporal
Release
2026-02-28
Signals
Mariner Unknown impact Exploited: n/a Publicly disclosed: n/a Exploitability: n/a
CWE
Patch Diff
Loading module diff metadata...
Resolved binary override
Use this when the MSRC module name cannot be mapped automatically or the resolved binary looks wrong.
Old version New version
Description
No description was published by MSRC.
FAQ / Articles
No FAQ or article content was published.