CVE-2026-87736
Linux Debian Analisi e mitigazione delle vulnerabilità

Panoramica

CVE-2026-87736 is an out-of-bounds read vulnerability in the mirage-crypto-ec package for OCaml, triggered when processing compressed elliptic curve (EC) public keys. It affects all versions of mirage-crypto-ec before 2.3.0. The vulnerability was published on September 9, 2026, and carries a CVSS v3.1 base score of 4.3 (Medium) (GitHub Advisory).

Dettagli tecnici

The root cause is an out-of-bounds read (CWE-125) in the EC public key parsing logic of mirage-crypto-ec, specifically when handling compressed elliptic curve points. An authenticated, network-adjacent attacker can supply a malformed compressed EC public key that causes the library to read memory beyond the intended buffer boundary. No special configuration is required beyond having the library process attacker-supplied compressed EC points; the attacker must be authenticated (low privileges required). The vulnerability is tracked under CAPEC-540 (Overread Buffers) (GitHub Advisory).

Impatto

Successful exploitation can cause the application using mirage-crypto-ec to crash, resulting in a denial-of-service condition. The confidentiality and integrity impacts are assessed as none, meaning data exposure or modification is not a direct consequence. The availability impact is rated low, limiting the practical effect to application-level disruption rather than full system compromise (GitHub Advisory).

Sfruttabilità

There is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the disclosure date. The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires low-level authentication, further reducing the attack surface (GitHub Advisory).

Mitigazione e soluzioni alternative

The fix is available in mirage-crypto-ec version 2.3.0 and later; upgrading to this version is the recommended remediation. If immediate patching is not feasible, operators should restrict network access to services that use this library and limit access to authenticated users only. No additional workarounds have been published (GitHub Advisory).

Risorse aggiuntive

Stato della correzione della distribuzione Linux

Correggi la disponibilità tra le principali distribuzioni Linux e le loro versioni.

Debian

Fisso

bookworm

ocaml-mirage-crypto

Interessati

sid

ocaml-mirage-crypto: 2.3.0-1

Fisso

trixie

ocaml-mirage-crypto

Interessati

Ubuntu

Sconosciuto

devel

ocaml-mirage-crypto

Sconosciuto

jammy

ocaml-mirage-crypto

Sconosciuto

jammy (esm-apps)

ocaml-mirage-crypto

Sconosciuto

noble

ocaml-mirage-crypto

Sconosciuto

noble (esm-apps)

ocaml-mirage-crypto

Sconosciuto

resolute

ocaml-mirage-crypto

Sconosciuto

resolute (esm-apps)

ocaml-mirage-crypto

Sconosciuto

FonteQuesto report è stato generato utilizzando l'intelligenza artificiale

Imparentato Linux Debian Vulnerabilità:

CVE ID

Severità

Punteggio

Tecnologie

Nome del componente

Exploit CISA KEV

Ha la correzione

Data di pubblicazione

CVE-2026-87733MEDIUM6.2
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026
CVE-2026-87732MEDIUM6.2
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026
CVE-2026-87737MEDIUM5.9
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026
CVE-2026-87736MEDIUM4.3
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026
CVE-2026-87735MEDIUM4.3
  • Linux Debian logoLinux Debian
  • ocaml-mirage-crypto
NoSep 09, 2026

Valutazione gratuita delle vulnerabilità

Benchmark della tua posizione di sicurezza del cloud

Valuta le tue pratiche di sicurezza cloud in 9 domini di sicurezza per confrontare il tuo livello di rischio e identificare le lacune nelle tue difese.

Richiedi valutazione

Richiedi una demo personalizzata

Pronti a vedere Wiz in azione?

"La migliore esperienza utente che abbia mai visto offre piena visibilità ai carichi di lavoro cloud."
David EstlickCISO (CISO)
"Wiz fornisce un unico pannello di controllo per vedere cosa sta succedendo nei nostri ambienti cloud."
Adam FletcherResponsabile della sicurezza
"Sappiamo che se Wiz identifica qualcosa come critico, in realtà lo è."
Greg PoniatowskiResponsabile della gestione delle minacce e delle vulnerabilità