<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 17:16:01 +0000</lastBuildDate>
    <item>
      <title>CVE-2026-28364</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2026-28364</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; OCaml, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images&lt;/p&gt;
&lt;p&gt;In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; OCaml, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat Hardened Images&lt;/p&gt;
&lt;p&gt;In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2026-28364</guid>
    </item>
    <item>
      <title>OSEC-2026-18 — Marshal integer overflow leads to out-of-heap read</title>
      <link>https://cve.radiocsirt.org/vuln/osec-2026-18</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; opam: ocaml&lt;/p&gt;
&lt;p&gt;An integer overflow in the length-validation logic of OCaml&amp;#39;s Marshal deserializer allows a crafted serialized object to bypass all bounds checks added by the CVE-2026-28364 fix, producing **heap out-of-bounds reads** from `Marshal.from_bytes` / `Marshal.from_string` (and the C API `caml_input_value_from_block`).&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;`runtime/intern.c` validates declared data length against the input buffer with unsigned 64-bit addition that can wrap:&lt;/p&gt;
&lt;p&gt;```c
/* caml_input_val_from_bytes, intern.c:1038 */
if (ofs + h.header_len + h.data_len &amp;gt; caml_string_length(str))
  caml_failwith(&amp;#34;input_val_from_string: bad length&amp;#34;);
```&lt;/p&gt;
&lt;p&gt;`h.data_len` is fully attacker-controlled (8-byte field read straight from the stream for `Intext_magic_number_big`). With `data_len &amp;gt;= 2^64 - (ofs + h.header_len)`, the sum wraps to a small value and the check passes.&lt;/p&gt;
&lt;p&gt;The CVE-2026-28364 fix introduced:&lt;/p&gt;
&lt;p&gt;```c
/* intern.c:1043 (added by the fix) */
s-&amp;gt;intern_src_end = s-&amp;gt;intern_src + h.data_len;   /* wraps to a pointer BEFORE the buffer */
```&lt;/p&gt;
&lt;p&gt;`intern_src_end` wraps to a location *before* `intern_src`, so every `intern_check_read()` bound added by the fix (`len &amp;gt; end - src` with a negative diff promoted to a huge `uintnat`) evaluates **false** for any realistic length. The parser (`intern_rec`) then honors attacker-controlled read lengths (`readblock` up to `Max_wosize` bytes) against memory far beyond the input buffer.&lt;/p&gt;
&lt;p&gt;The OCaml-side wrapper validation in `stdlib/marshal.ml` is bypassed by the same wrap, via…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; opam: ocaml&lt;/p&gt;
&lt;p&gt;An integer overflow in the length-validation logic of OCaml&amp;#39;s Marshal deserializer allows a crafted serialized object to bypass all bounds checks added by the CVE-2026-28364 fix, producing **heap out-of-bounds reads** from `Marshal.from_bytes` / `Marshal.from_string` (and the C API `caml_input_value_from_block`).&lt;/p&gt;
&lt;p&gt;## Root cause&lt;/p&gt;
&lt;p&gt;`runtime/intern.c` validates declared data length against the input buffer with unsigned 64-bit addition that can wrap:&lt;/p&gt;
&lt;p&gt;```c
/* caml_input_val_from_bytes, intern.c:1038 */
if (ofs + h.header_len + h.data_len &amp;gt; caml_string_length(str))
  caml_failwith(&amp;#34;input_val_from_string: bad length&amp;#34;);
```&lt;/p&gt;
&lt;p&gt;`h.data_len` is fully attacker-controlled (8-byte field read straight from the stream for `Intext_magic_number_big`). With `data_len &amp;gt;= 2^64 - (ofs + h.header_len)`, the sum wraps to a small value and the check passes.&lt;/p&gt;
&lt;p&gt;The CVE-2026-28364 fix introduced:&lt;/p&gt;
&lt;p&gt;```c
/* intern.c:1043 (added by the fix) */
s-&amp;gt;intern_src_end = s-&amp;gt;intern_src + h.data_len;   /* wraps to a pointer BEFORE the buffer */
```&lt;/p&gt;
&lt;p&gt;`intern_src_end` wraps to a location *before* `intern_src`, so every `intern_check_read()` bound added by the fix (`len &amp;gt; end - src` with a negative diff promoted to a huge `uintnat`) evaluates **false** for any realistic length. The parser (`intern_rec`) then honors attacker-controlled read lengths (`readblock` up to `Max_wosize` bytes) against memory far beyond the input buffer.&lt;/p&gt;
&lt;p&gt;The OCaml-side wrapper validation in `stdlib/marshal.ml` is bypassed by the same wrap, via…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/osec-2026-18</guid>
    </item>
  </channel>
</rss>
