https://seclists.org/oss-sec/2026/q1/241: OSEC-2026-01 in the OCaml runtime: Buffer Over-ad in OCaml Marshal Deserialization
Published Mar 2, 2026
·Updated
Affected Software
1 affected component
ocaml OCaml Runtime
Frequently Asked Questions
1
What is the severity of OSEC-2026-01 in the OCaml runtime?
The severity of OSEC-2026-01 is considered high due to the potential for remote code execution.
2
How do I fix OSEC-2026-01 in the OCaml runtime?
To fix OSEC-2026-01, update the OCaml runtime to the latest patched version provided by the maintainers.
3
What is the impact of OSEC-2026-01 in the OCaml runtime?
The impact of OSEC-2026-01 includes vulnerability to buffer over-reads, leading to possible exposure of sensitive information.
4
What system versions are affected by OSEC-2026-01?
OSEC-2026-01 affects all versions of the OCaml runtime prior to the patch released on March 2, 2026.
5
Is OSEC-2026-01 related to any other vulnerabilities?
OSEC-2026-01 may share characteristics with other buffer overflow vulnerabilities, but it is specific to OCaml's marshal deserialization processes.