<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T12:19:53.121281+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-28364</id>
    <title>CVE-2026-28364</title>
    <updated>2026-10-02T12:19:53.123611+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OCaml, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images</p>
<p>In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-28364"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/osec-2026-01</id>
    <title>OSEC-2026-01 — Buffer Over-Read in OCaml Marshal Deserialization</title>
    <updated>2026-10-02T12:19:53.123683+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> opam: ocaml</p>
<p>## Summary</p>
<p>A critical buffer over-read vulnerability in OCaml's Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from malicious Marshal data.</p>
<p>Please note that Marshal is not type safe, and you have to be careful if you use the deserialization on untrusted input (due to type confusion, and remote code execution by design - you can use Marshal for code).</p>
<p>Affected functions: `Marshal.from_channel`, `Marshal.from_bytes`, `Marshal.from_string`, `Stdlib.input_value`, `Pervasives.input_value` when reading data from an untrusted source.</p>
<p>## Vulnerability Attack Vector</p>
<p>Corrupted or malicious marshaled data that causes undefined behaviour in the runtime system when unmarshaled.
`input_value` should either fail cleanly or produce a well-formed OCaml object, without corrupting the runtime system.</p>
<p>Consequently, this excludes:</p>
<p>* well-formed marshaled data that produces an OCaml object that is not of the type expected by the OCaml code and causes the Ocaml code to crash or misbehave</p>
<p>* misuses of the OCaml runtime system by the program performing input_value, such as setting `Debugger.function_placeholder` to the wrong function.</p>
<p>The former issue may be addressed at some point by validating the unmarshaled OCaml value against the expected type, using the functions…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/osec-2026-01"/>
  </entry>
</feed>
