All errata/sisyphus_e2k/ALT-PU-2026-6448-1
ALT-PU-2026-6448-1

Package update ocaml in branch sisyphus_e2k

Version5.4.1-alt1
Task#0
Published2026-04-17
Max severityHIGH
Severity:

Closed issues (1)

CVE-2026-28364
HIGH7.8

In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.

Published: 2026-02-27Modified: 2026-03-06
CVSS 3.xHIGH 7.8
CVSS:3.x/CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H