
PEACH
Un framework di isolamento del tenant
CVE-2026-87736 is an out-of-bounds read vulnerability in the mirage-crypto-ec package for OCaml, triggered when processing compressed elliptic curve (EC) public keys. It affects all versions of mirage-crypto-ec before 2.3.0. The vulnerability was published on September 9, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory).
The root cause is an out-of-bounds read (CWE-125) in the EC public key parsing logic of mirage-crypto-ec, specifically when handling compressed elliptic curve points. An authenticated, network-adjacent attacker can supply a malformed compressed EC public key that causes the library to read memory beyond the intended buffer boundary. No special configuration is required beyond having the library process attacker-supplied compressed EC points; the attacker must be authenticated (low privileges required). The vulnerability is tracked under CAPEC-540 (Overread Buffers) (GitHub Advisory).
Successful exploitation can cause the application using mirage-crypto-ec to crash, resulting in a denial-of-service condition. The confidentiality and integrity impacts are assessed as none, meaning data exposure or modification is not a direct consequence. The availability impact is rated low, limiting the practical effect to application-level disruption rather than full system compromise (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the disclosure date. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low-level authentication, further reducing the attack surface (GitHub Advisory).
The fix is available in mirage-crypto-ec version 2.3.0 and later; upgrading to this version is the recommended remediation. If immediate patching is not feasible, operators should restrict network access to services that use this library and limit access to authenticated users only. No additional workarounds have been published (GitHub Advisory).
Correggi la disponibilità tra le principali distribuzioni Linux e le loro versioni.
bookworm
ocaml-mirage-crypto
sid
ocaml-mirage-crypto: 2.3.0-1
trixie
ocaml-mirage-crypto
devel
ocaml-mirage-crypto
jammy
ocaml-mirage-crypto
jammy (esm-apps)
ocaml-mirage-crypto
noble
ocaml-mirage-crypto
noble (esm-apps)
ocaml-mirage-crypto
resolute
ocaml-mirage-crypto
resolute (esm-apps)
ocaml-mirage-crypto
Fonte: Questo report è stato generato utilizzando l'intelligenza artificiale
Valutazione gratuita delle vulnerabilità
Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.
Richiedi una demo personalizzata
"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."