CVE-2026-28364
OCaml OCaml, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6 취약점
In OCaml before 4.14.3 and 5.x before 5.4.1, a buffer over-read in Marshal deserialization (runtime/intern.c) enables remote code execution through a multi-phase attack chain. The vulnerability stems from missing bounds validation in the readblock() function, which performs unbounded memcpy() operations using attacker-controlled lengths from crafted Marshal data.
- 대응 우선순위
- 점검
- CVSS
- 7.8
- EPSS
- 0.21% 백분위 11.3% · 2026.08.04 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.02.27