CVE-2026-28364

HIGH

OCaml <4.14.3/5.x<5.4.1 - Buffer Overflow

Title source: llm
STIX 2.1

Description

In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.

Scores

CVSS v3 7.9
EPSS 0.0004
EPSS Percentile 13.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-126
Status published
Products (1)
ocaml/ocaml < 4.14.3
Published Feb 27, 2026
Tracked Since Feb 27, 2026