Source: ocaml-cstruct Version: 6.2.0-4 Severity: important Tags: security upstream X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for ocaml-cstruct. CVE-2026-89087[0]: | The cstruct package before 6.3.0 for OCaml mishandles indexes. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-89087 https://www.cve.org/CVERecord?id=CVE-2026-89087 [1] https://osv.dev/vulnerability/OSEC-2026-20 [2] https://github.com/mirage/ocaml-cstruct/pull/324 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

