MSRC compact vulnerability detail
CVE-2026-28364 · In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.
No description was published by MSRC.
Signals
Mariner
Unknown impact
Exploited: n/a
Publicly disclosed: n/a
Exploitability: n/a
CWE
Patch Diff
Loading module diff metadata...
Resolved binary override
Use this when the MSRC module name cannot be mapped automatically or the resolved binary looks wrong.
Description
No description was published by MSRC.
FAQ / Articles
No FAQ or article content was published.