Impact
The utcp package for OCaml contains a flaw that permits an attacker to send TCP packets out of order, causing the reassembly logic to misprocess data and ultimately crash the service. This issue is classified as CWE‑923: Out‑of‑Order Data Processing and results in a denial of service that can be triggered without authentication.
Affected Systems
Any deployment of the utcp library older than version 0.0.6 is affected. The vulnerability is present in the OCaml:utcp package distributed by the OCaml community.
Risk and Exploitability
The flaw carries a CVSS score of 7.5, indicating a moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation yet. The likely attack vector involves an untrusted remote host sending crafted segments to the utcp listener; no local privileges or authentication are required to trigger the crash. Because the service can be made unavailable by an external attacker, immediate remediation is advised.
OpenCVE Enrichment