{"id":"UBUNTU-CVE-2026-89087","details":"The cstruct package before 6.3.0 for OCaml mishandles indexes.","modified":"2026-09-16T11:43:12Z","published":"2026-09-10T20:17:00Z","upstream":["CVE-2026-89087"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-89087"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-89087"},{"type":"REPORT","url":"https://osv.dev/vulnerability/OSEC-2026-20"},{"type":"REPORT","url":"https://github.com/mirage/ocaml-cstruct/pull/324"}],"affected":[{"package":{"name":"ocaml-cstruct","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/ocaml-cstruct?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.0.0-1build1","6.0.1-1build1","6.0.1-1build3"],"ecosystem_specific":{"binaries":[{"binary_name":"libcstruct-ocaml","binary_version":"6.0.1-1build3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-89087.json"}},{"package":{"name":"ocaml-cstruct","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/ocaml-cstruct?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.2.0-2build1","6.2.0-2build2","6.2.0-2build3"],"ecosystem_specific":{"binaries":[{"binary_name":"libcstruct-ocaml","binary_version":"6.2.0-2build3"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-89087.json"}},{"package":{"name":"ocaml-cstruct","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/ocaml-cstruct?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["6.2.0-3build9","6.2.0-3build10","6.2.0-3build11","6.2.0-3build13"],"ecosystem_specific":{"binaries":[{"binary_version":"6.2.0-3build13","binary_name":"libcstruct-ocaml"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-89087.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L"},{"type":"Ubuntu","score":"medium"}]}