<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T12:26:23.090202+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cve-2026-28364</id>
    <title>CVE-2026-28364</title>
    <updated>2026-10-04T12:26:23.127024+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> OCaml, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images</p>
<p>In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/cve-2026-28364"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/osec-2026-18</id>
    <title>OSEC-2026-18 — Marshal integer overflow leads to out-of-heap read</title>
    <updated>2026-10-04T12:26:23.127089+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> opam: ocaml</p>
<p>An integer overflow in the length-validation logic of OCaml's Marshal deserializer allows a crafted serialized object to bypass all bounds checks added by the CVE-2026-28364 fix, producing **heap out-of-bounds reads** from `Marshal.from_bytes` / `Marshal.from_string` (and the C API `caml_input_value_from_block`).</p>
<p>## Root cause</p>
<p>`runtime/intern.c` validates declared data length against the input buffer with unsigned 64-bit addition that can wrap:</p>
<p>```c
/* caml_input_val_from_bytes, intern.c:1038 */
if (ofs + h.header_len + h.data_len &gt; caml_string_length(str))
  caml_failwith("input_val_from_string: bad length");
```</p>
<p>`h.data_len` is fully attacker-controlled (8-byte field read straight from the stream for `Intext_magic_number_big`). With `data_len &gt;= 2^64 - (ofs + h.header_len)`, the sum wraps to a small value and the check passes.</p>
<p>The CVE-2026-28364 fix introduced:</p>
<p>```c
/* intern.c:1043 (added by the fix) */
s-&gt;intern_src_end = s-&gt;intern_src + h.data_len;   /* wraps to a pointer BEFORE the buffer */
```</p>
<p>`intern_src_end` wraps to a location *before* `intern_src`, so every `intern_check_read()` bound added by the fix (`len &gt; end - src` with a negative diff promoted to a huge `uintnat`) evaluates **false** for any realistic length. The parser (`intern_rec`) then honors attacker-controlled read lengths (`readblock` up to `Max_wosize` bytes) against memory far beyond the input buffer.</p>
<p>The OCaml-side wrapper validation in `stdlib/marshal.ml` is bypassed by the same wrap, via…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/osec-2026-18"/>
  </entry>
</feed>
