Back Linuxsecurity Fedora 45 ocaml-uuseg Security Bugs Advisory CVE-2026
Running self-managed GitLab? Critical flaws could allow server code execution. Check the fixes. ×
Uuseg is an OCaml library for segmenting Unicode text. It implements the
locale-independent Unicode text segmentation algorithms
( to detect grapheme cluster, word and
sentence boundaries and the Unicode line breaking algorithm
( to detect line break opportunities.
The library is independent from any IO mechanism or Unicode text data
structure and it can process text without a complete in-memory representation.
Uuseg depends on Uucp and optionally on Uutf for support for OCaml UTF-X
encoded strings. It is distributed under the ISC license.
This is a mass rebuild of the OCaml ecosystem with OCaml 5.5.1, which fixes two security bugs. See for details. In addition, rocq has been updated to version 9.3.0, which also fixes several CVEs. New upstream development version 1.61.4 New upstream development version 2.13.7
* Thu Sep 24 2026 Jerry James - 18.0.0-2 - Ensure the Unicode test files versions match * Fri Sep 18 2026 Jerry James - 18.0.0-1 - Version 18.0.0 - Revert changes for an unreleased version of ocaml-b0 * Tue Sep 15 2026 Richard W.M. Jones - 17.0.0-9 - OCaml 5.5.1 rebuild
* Thu Sep 24 2026 Jerry James - 18.0.0-2 - Ensure the Unicode test files versions match * Fri Sep 18 2026 Jerry James - 18.0.0-1 - Version 18.0.0 - Revert changes for an unreleased version of ocaml-b0 * Tue Sep 15 2026 Richard W.M. Jones - 17.0.0-9 - OCaml 5.5.1 rebuild
[ 1 ] Bug #2443780 - CVE-2026-28364 ocaml: OCaml: Remote code execution via buffer over-read in Marshal deserialization [fedora-all] [ 2 ] Bug #2520289 - rocq-stdlib-9.2.0 is available [ 3 ] Bug #2523138 - CVE-2020-37268 rocq: Coq and Rocq Provers: Logical inconsistency bypass via Print Assumptions omission [fedora-all] [ 4 ] Bug #2523145 - CVE-2026-72703 rocq: Rocq Prover: Logical Flaw Allows Arbitrary Proof Generation via Unchecked Cross-Calls [fedora-all] [ 5 ] Bug #2523146 - CVE-2026-72705 rocq: Rocq Prover: Logical inconsistency via untracked higher-order fixpoint arguments [fedora-all] [ 6 ] Bug #2523147 - CVE-2026-72714 rocq: Rocq Prover: Critical integrity by...
This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-403bcf6fd8' at the command line. For more information, refer to the dnf documentation available at
Get the latest News and Insights
Get the latest Linux and open source security news straight to your inbox.
Linux Security - Your source for Top Linux News, Advisories, HOWTOs and Feature Releases
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
