<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 08:59:46 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0284 — De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Elles permettent à un attaquant de provoqu…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0284</link>
      <description>certfr-2026-avi-0284</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0284</guid>
    </item>
    <item>
      <title>EUVD-2026-337387</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337387</link>
      <description>EUVD-2026-337387</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337387</guid>
    </item>
    <item>
      <title>fkie_cve-2026-28364</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-28364</link>
      <description>&lt;p&gt;In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-28364</guid>
    </item>
    <item>
      <title>GHSA-g54x-7hpm-29q8</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-g54x-7hpm-29q8</link>
      <description>&lt;p&gt;In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-g54x-7hpm-29q8</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-28364 — In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables r…</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-28364</link>
      <description>msrc_CVE-2026-28364</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-28364</guid>
    </item>
    <item>
      <title>OESA-2026-1522 — ocaml security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2026-1522</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: ocaml&lt;/p&gt;
&lt;p&gt;OCaml is a high-level, strongly-typed, functional and object-oriented programming language from the ML family of languages. This package includes runtime environment, X11 support ,Documentation generator and emacs.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.(CVE-2026-28364)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:22.03-LTS-SP4: ocaml&lt;/p&gt;
&lt;p&gt;OCaml is a high-level, strongly-typed, functional and object-oriented programming language from the ML family of languages. This package includes runtime environment, X11 support ,Documentation generator and emacs.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.(CVE-2026-28364)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2026-1522</guid>
    </item>
    <item>
      <title>openSUSE-SU-2026:11136-1 — ocaml-4.14.4-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2026:11136-1</link>
      <description>&lt;p&gt;ocaml-4.14.4-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;ocaml-4.14.4-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2026:11136-1</guid>
    </item>
    <item>
      <title>OSEC-2026-01 — Buffer Over-Read in OCaml Marshal Deserialization</title>
      <link>https://cve.radiocsirt.org/vuln/osec-2026-01</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; opam: ocaml&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A critical buffer over-read vulnerability in OCaml&amp;#39;s Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from malicious Marshal data.&lt;/p&gt;
&lt;p&gt;Please note that Marshal is not type safe, and you have to be careful if you use the deserialization on untrusted input (due to type confusion, and remote code execution by design - you can use Marshal for code).&lt;/p&gt;
&lt;p&gt;Affected functions: `Marshal.from_channel`, `Marshal.from_bytes`, `Marshal.from_string`, `Stdlib.input_value`, `Pervasives.input_value` when reading data from an untrusted source.&lt;/p&gt;
&lt;p&gt;## Vulnerability Attack Vector&lt;/p&gt;
&lt;p&gt;Corrupted or malicious marshaled data that causes undefined behaviour in the runtime system when unmarshaled.
`input_value` should either fail cleanly or produce a well-formed OCaml object, without corrupting the runtime system.&lt;/p&gt;
&lt;p&gt;Consequently, this excludes:&lt;/p&gt;
&lt;p&gt;* well-formed marshaled data that produces an OCaml object that is not of the type expected by the OCaml code and causes the Ocaml code to crash or misbehave&lt;/p&gt;
&lt;p&gt;* misuses of the OCaml runtime system by the program performing input_value, such as setting `Debugger.function_placeholder` to the wrong function.&lt;/p&gt;
&lt;p&gt;The former issue may be addressed at some point by validating the unmarshaled OCaml value against the expected type, using the functions…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; opam: ocaml&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;A critical buffer over-read vulnerability in OCaml&amp;#39;s Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from malicious Marshal data.&lt;/p&gt;
&lt;p&gt;Please note that Marshal is not type safe, and you have to be careful if you use the deserialization on untrusted input (due to type confusion, and remote code execution by design - you can use Marshal for code).&lt;/p&gt;
&lt;p&gt;Affected functions: `Marshal.from_channel`, `Marshal.from_bytes`, `Marshal.from_string`, `Stdlib.input_value`, `Pervasives.input_value` when reading data from an untrusted source.&lt;/p&gt;
&lt;p&gt;## Vulnerability Attack Vector&lt;/p&gt;
&lt;p&gt;Corrupted or malicious marshaled data that causes undefined behaviour in the runtime system when unmarshaled.
`input_value` should either fail cleanly or produce a well-formed OCaml object, without corrupting the runtime system.&lt;/p&gt;
&lt;p&gt;Consequently, this excludes:&lt;/p&gt;
&lt;p&gt;* well-formed marshaled data that produces an OCaml object that is not of the type expected by the OCaml code and causes the Ocaml code to crash or misbehave&lt;/p&gt;
&lt;p&gt;* misuses of the OCaml runtime system by the program performing input_value, such as setting `Debugger.function_placeholder` to the wrong function.&lt;/p&gt;
&lt;p&gt;The former issue may be addressed at some point by validating the unmarshaled OCaml value against the expected type, using the functions…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/osec-2026-01</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-28364</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-28364</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ocaml, Ubuntu:Pro:16.04:LTS: ocaml, Ubuntu:Pro:18.04:LTS: ocaml, Ubuntu:20.04:LTS: ocaml, Ubuntu:22.04:LTS: ocaml, Ubuntu:24.04:LTS: ocaml, Ubuntu:25.10: ocaml, Ubuntu:26.04:LTS: ocaml&lt;/p&gt;
&lt;p&gt;In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:14.04:LTS: ocaml, Ubuntu:Pro:16.04:LTS: ocaml, Ubuntu:Pro:18.04:LTS: ocaml, Ubuntu:20.04:LTS: ocaml, Ubuntu:22.04:LTS: ocaml, Ubuntu:24.04:LTS: ocaml, Ubuntu:25.10: ocaml, Ubuntu:26.04:LTS: ocaml&lt;/p&gt;
&lt;p&gt;In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-28364</guid>
    </item>
  </channel>
</rss>
