PT-2026-28619 · Ocaml · Ocaml

Published

2026-03-27

·

Updated

2026-04-11

·

CVE-2026-34353

CVSS v3.1

5.9

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions OCaml versions through 4.14.3
Description The Bigarray.reshape function in OCaml versions through 4.14.3 contains an integer overflow issue. This can lead to arbitrary memory being read when processing untrusted data. The function Bigarray.reshape is susceptible to this issue.
Recommendations Update to a version of OCaml newer than 4.14.3. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Weakness Enumeration

Related Identifiers

CVE-2026-34353
OESA-2026-1889
OESA-2026-1890
OESA-2026-1891
OESA-2026-1892
OESA-2026-1893

Affected Products

Ocaml