CVE-2026-34353

Name
CVE-2026-34353
Description
In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
cve@mitre.org https://github.com/ocaml/ocaml/issues/14655
cve@mitre.org https://github.com/ocaml/ocaml/pull/14674

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:ocaml:ocaml:*:*:*:*:*:*:*:* ocaml >= None <= 4.14.3

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
ocaml edge-community 4.14.3-r0 omni <omni+alpine@hack.org> possibly vulnerable
ocaml edge-community 4.14.2-r2 omni <omni+alpine@hack.org> possibly vulnerable
ocaml edge-community 4.14.2-r1 omni <omni+alpine@hack.org> possibly vulnerable
ocaml 3.23-community 4.14.2-r2 omni <omni+alpine@hack.org> possibly vulnerable