Skip to content
Vulnerabilities in OCaml Libraries Affecting Fedora 45

Vulnerabilities in OCaml Libraries Affecting Fedora 45

First seen 6 Oct 2026, 11:26 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 6, 2026 at 12:58 UTC
  • •Multiple critical vulnerabilities in OCaml libraries for Fedora 45, including CVE-2026-28364.
  • •Remote code execution risk due to buffer over-read vulnerabilities.
  • •Patches are available and should be applied immediately to affected systems.

A mass rebuild of the OCaml ecosystem for Fedora 45 has addressed multiple vulnerabilities, including CVE-2026-28364, which allows remote code execution via buffer over-read in Marshal deserialization. This vulnerability affects various OCaml libraries, including ocaml-stdcompat, ocaml-uuseg, and others. The issues were disclosed on 2026-02-27, with a proof of concept released on 2026-09-24. The vulnerabilities impact users of Fedora 45 and require immediate attention to apply the patches provided. Other CVEs, such as CVE-2026-72703, CVE-2026-72705, and CVE-2020-37268, also received fixes in this update. Users are urged to upgrade their systems to mitigate the risks associated with these vulnerabilities.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-02-27
CVE-2026-28364 published
A remote code execution vulnerability in OCaml libraries was disclosed.
Linuxsecurity
2026-08-24
CVE-2026-72714 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-24
CVE-2026-72705 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-24
CVE-2020-37268 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-24
CVE-2026-72703 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-24
Proof of concept released
Public proof of concept for CVE-2026-28364 was made available, increasing exploitation risk.
Linuxsecurity
2026-10-06
Patches released
Fedora 45 released patches for multiple OCaml libraries to address critical vulnerabilities.
Linuxsecurity

More articles in this cluster (42)

Following this threat?

Track Fedora and CVE-2020-37268 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which OCaml libraries are affected?
Affected libraries include ocaml-stdcompat, ocaml-uuseg, and others in the OCaml ecosystem.
What is the risk level of these vulnerabilities?
The vulnerabilities pose a high risk of remote code execution, particularly CVE-2026-28364.
How can I mitigate these vulnerabilities?
Users should immediately apply the patches released for Fedora 45 to secure their systems.