CVE-2026-87735
Linux Debian Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-87735 is a denial-of-service vulnerability in the mirage-crypto-pk package for OCaml, caused by an undocumented exception triggered when processing small messages during RSA decryption or encryption operations. It affects all versions of mirage-crypto-pk before 2.3.0. The vulnerability was published on September 9, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory).

Dettagli tecnici

The root cause is classified as CWE-1284 (Improper Validation of Specified Quantity in Input): the library fails to validate or properly handle message size inputs before passing them to RSA cryptographic operations, resulting in an undocumented exception being raised for unexpectedly small messages. An authenticated, network-accessible attacker can trigger this exception by submitting a crafted small message to any service endpoint that invokes mirage-crypto-pk's RSA encrypt or decrypt functions. No public proof-of-concept code has been identified at this time (GitHub Advisory, OSV).

Impatto

Successful exploitation causes the RSA encryption or decryption operation to raise an unhandled exception, which can crash the affected cryptographic service or cause the operation to fail entirely, resulting in a loss of availability. The impact is limited to availability (low severity per CVSS), with no confidentiality or integrity compromise. Services built on mirage-crypto-pk that expose RSA operations to authenticated users are at risk of disruption, but lateral movement or data exfiltration are not direct consequences of this vulnerability (GitHub Advisory).

Sfruttabilità

There is no evidence of active in-the-wild exploitation or publicly available proof-of-concept code for CVE-2026-87735. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability requires low-privilege authenticated access over the network, which somewhat limits the attack surface. It has not been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (GitHub Advisory).

Mitigazione e soluzioni alternative

Upgrade the mirage-crypto-pk package to version 2.3.0 or later, which resolves the undocumented exception. As a complementary measure, implement input validation at the application layer to reject or sanitize unexpectedly small messages before they are passed to RSA operations. Adding exception handling around RSA encrypt/decrypt calls can also help prevent service crashes in the interim (GitHub Advisory).

Risorse aggiuntive

Stato della correzione della distribuzione Linux

Correggi la disponibilità tra le principali distribuzioni Linux e le loro versioni.

Debian

Fisso

bookworm

ocaml-mirage-crypto

Interessati

sid

ocaml-mirage-crypto: 2.3.0-1

Fisso

trixie

ocaml-mirage-crypto

Interessati

Ubuntu

Sconosciuto

devel

ocaml-mirage-crypto

Sconosciuto

jammy

ocaml-mirage-crypto

Sconosciuto

jammy (esm-apps)

ocaml-mirage-crypto

Sconosciuto

noble

ocaml-mirage-crypto

Sconosciuto

noble (esm-apps)

ocaml-mirage-crypto

Sconosciuto

resolute

ocaml-mirage-crypto

Sconosciuto

resolute (esm-apps)

ocaml-mirage-crypto

Sconosciuto

FonteQuesto report è stato generato utilizzando l'intelligenza artificiale

Imparentato Linux Debian Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-87733MEDIUM6.2
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026
CVE-2026-87732MEDIUM6.2
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026
CVE-2026-87737MEDIUM5.9
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026
CVE-2026-87736MEDIUM4.3
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026
CVE-2026-87735MEDIUM4.3
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità