Security NewsCriticalIncidentvulnerability
CVE-2026-28364 In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.
UnknownMar 8, 2026(about 1 hour ago)
A buffer over-read vulnerability in OCaml's Marshal deserialization allows remote code execution through crafted Marshal data.
Information published.
Related CVEs
Related News
OpenAI Codex Security Scanned 1.2 Million Commits and Found 10,561 High-Severity Issues
Unknownabout 18 hours ago
Termite ransomware breaches linked to ClickFix CastleRAT attacks
Unknownabout 18 hours ago
US Cyber Strategy Targets Adversaries, Critical Infrastructure, and Emerging Technologies
Unknownabout 18 hours ago