rpm package
opensuse/ocaml&distro=openSUSE Tumbleweed
pkg:rpm/opensuse/ocaml&distro=openSUSE%20Tumbleweed
Vulnerabilities (2)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-34353 | Med | 5.9 | < 4.14.4-1.1 | 4.14.4-1.1 | Mar 27, 2026 | In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed. | |
| CVE-2026-28364 | Hig | 7.9 | < 4.14.4-1.1 | 4.14.4-1.1 | Feb 27, 2026 | In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbou |
- affected < 4.14.4-1.1fixed 4.14.4-1.1
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
- affected < 4.14.4-1.1fixed 4.14.4-1.1
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbou