{"id":"UBUNTU-CVE-2026-87732","details":"An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The AES.GCM.authenticate_decrypt_into and Chacha20.authenticate_decrypt_into functions write the decrypted plaintext into a caller-provided buffer and only then compares the tag. On a forged tag, the functions returns false, but the destination buffer already holds the full plaintext.","modified":"2026-09-16T14:03:37.723926877Z","published":"2026-09-09T05:18:00Z","upstream":["CVE-2026-87732"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-87732"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-87732"},{"type":"REPORT","url":"https://osv.dev/vulnerability/OSEC-2026-12"}],"affected":[{"package":{"name":"ocaml-mirage-crypto","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/ocaml-mirage-crypto?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.10.5-4","0.10.5-4build2"],"ecosystem_specific":{"binaries":[{"binary_name":"libmirage-crypto-ocaml","binary_version":"0.10.5-4build2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-87732.json"}},{"package":{"name":"ocaml-mirage-crypto","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/ocaml-mirage-crypto?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.11.1-3","0.11.2-1","0.11.2-1build1","0.11.2-2build3"],"ecosystem_specific":{"binaries":[{"binary_name":"libmirage-crypto-ocaml","binary_version":"0.11.2-2build3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-87732.json"}},{"package":{"name":"ocaml-mirage-crypto","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/ocaml-mirage-crypto?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.0.1-1build1","2.0.2-1build1","2.0.2-1build2","2.0.2-1build3","2.0.2-1build5"],"ecosystem_specific":{"binaries":[{"binary_version":"2.0.2-1build5","binary_name":"libmirage-crypto-ocaml"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-87732.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]}