CVE-2026-34353

In OCaml through 4.14.3, Bigarray.reshape allows an integer overflow, and resultant reading of arbitrary memory, when untrusted data is processed.
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:ocaml:ocaml:*:*:*:*:*:*:*:*

History

14 Apr 2026, 18:43

Type Values Removed Values Added
CPE cpe:2.3:a:ocaml:ocaml:*:*:*:*:*:*:*:*
References () https://github.com/ocaml/ocaml/issues/14655 - () https://github.com/ocaml/ocaml/issues/14655 - Issue Tracking
References () https://github.com/ocaml/ocaml/pull/14674 - () https://github.com/ocaml/ocaml/pull/14674 - Issue Tracking
First Time Ocaml
Ocaml ocaml

27 Mar 2026, 06:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-03-27 06:16

Updated : 2026-04-14 18:43


NVD link : CVE-2026-34353

Mitre link : CVE-2026-34353

CVE.ORG link : CVE-2026-34353


JSON object : View

Products Affected

ocaml

  • ocaml
CWE
CWE-190

Integer Overflow or Wraparound