Linuxsecurity Vulnerabilities in OCaml Libraries Affecting Fedora 45
Article Content
- •Multiple critical vulnerabilities in OCaml libraries for Fedora 45, including CVE-2026-28364.
- •Remote code execution risk due to buffer over-read vulnerabilities.
- •Patches are available and should be applied immediately to affected systems.
A mass rebuild of the OCaml ecosystem for Fedora 45 has addressed multiple vulnerabilities, including CVE-2026-28364, which allows remote code execution via buffer over-read in Marshal deserialization. This vulnerability affects various OCaml libraries, including ocaml-stdcompat, ocaml-uuseg, and others. The issues were disclosed on 2026-02-27, with a proof of concept released on 2026-09-24. The vulnerabilities impact users of Fedora 45 and require immediate attention to apply the patches provided. Other CVEs, such as CVE-2026-72703, CVE-2026-72705, and CVE-2020-37268, also received fixes in this update. Users are urged to upgrade their systems to mitigate the risks associated with these vulnerabilities.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (42)
Following this threat?
Track Fedora and CVE-2020-37268 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which OCaml libraries are affected?
What is the risk level of these vulnerabilities?
How can I mitigate these vulnerabilities?
Continue Reading
Critical Authentication Bypass in Cisco Catalyst SD-WAN Manager Exploited On September 30, 2026, Cisco disclosed a critical vulnerability (CVE-2026-76504) in the Catalyst SD-WAN Manager that allows unauthenticated remote attackers to bypass authentication and gain admin-level access to the system. This flaw stems from improper handling of URI encoding in HTTP requests, enabling attackers to…