https://seclists.org/oss-sec/2026/q1/242: OSEC-2026-01 in the OCaml runtime: Buffer Over-ad in OCaml Marshal Deserialization
Published Mar 2, 2026
·Updated
Affected Software
1 affected component
ocaml OCaml Runtime
Frequently Asked Questions
1
What is the severity of OSEC-2026-01?
The severity of OSEC-2026-01 is critical due to its potential for remote exploitation.
2
How do I fix OSEC-2026-01?
To fix OSEC-2026-01, update the OCaml runtime to the recommended patched version provided in the security announcement.
3
What systems are affected by OSEC-2026-01?
OSEC-2026-01 affects all versions of the OCaml runtime prior to the patch release.
4
What is the nature of the vulnerability in OSEC-2026-01?
OSEC-2026-01 is a buffer over-read vulnerability occurring during OCaml Marshal deserialization.
5
What are the potential impacts of OSEC-2026-01?
The impacts of OSEC-2026-01 can include arbitrary code execution and data leakage.