https://seclists.org/oss-sec/2026/q1/247: OSEC-2026-01 in the OCaml runtime: Buffer Over-ad in OCaml Marshal Deserialization
Published Mar 3, 2026
·Updated
Affected Software
1 affected component
ocaml OCaml Runtime
Frequently Asked Questions
1
What is the severity of OSEC-2026-01 in the OCaml runtime?
OSEC-2026-01 is classified as a high severity vulnerability due to its potential for buffer over-read exploitation.
2
How do I fix OSEC-2026-01 in the OCaml runtime?
To fix OSEC-2026-01, you should update the OCaml runtime to the latest version that addresses this vulnerability.
3
What type of vulnerability is OSEC-2026-01?
OSEC-2026-01 is a buffer over-read vulnerability related to OCaml's Marshal deserialization process.
4
Which versions of OCaml are affected by OSEC-2026-01?
OSEC-2026-01 affects multiple versions of the OCaml runtime, and users are encouraged to check specific version details in the security announcement.
5
What are the potential impacts of OSEC-2026-01 exploitation?
Exploitation of OSEC-2026-01 may lead to data leakage and allow attackers to execute arbitrary code.