In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.
CVSS Details
- CVSS 3.1 Base Score: 7.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Amazon_linux_2023 | — | Upgrade ocaml-docsUpgrade ocaml-ocamldoc-debuginfoUpgrade ocamlUpgrade ocaml-ocamldocUpgrade ocaml-runtimeUpgrade ocaml-debugsourceUpgrade ocaml-sourceUpgrade ocaml-compiler-libsUpgrade ocaml-debuginfoUpgrade ocaml-runtime-debuginfo | Mar 27, 2026 | Feb 27, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 27, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub