Description
An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.
Published: 2026-09-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Apply Patch
AI Analysis

Impact

The utcp package for OCaml contains a flaw that permits an attacker to send TCP packets out of order, causing the reassembly logic to misprocess data and ultimately crash the service. This issue is classified as CWE‑923: Out‑of‑Order Data Processing and results in a denial of service that can be triggered without authentication.

Affected Systems

Any deployment of the utcp library older than version 0.0.6 is affected. The vulnerability is present in the OCaml:utcp package distributed by the OCaml community.

Risk and Exploitability

The flaw carries a CVSS score of 7.5, indicating a moderate to high severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting no confirmed exploitation yet. The likely attack vector involves an untrusted remote host sending crafted segments to the utcp listener; no local privileges or authentication are required to trigger the crash. Because the service can be made unavailable by an external attacker, immediate remediation is advised.

Generated by OpenCVE AI on September 9, 2026 at 11:41 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the utcp package to version 0.0.6 or newer.
  • Restart all applications that use utcp so that the updated library is loaded.
  • Implement input validation to enforce correct packet ordering before data processing.

Generated by OpenCVE AI on September 9, 2026 at 11:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Ocaml
Ocaml utcp
Vendors & Products Ocaml
Ocaml utcp

Wed, 09 Sep 2026 12:00:00 +0000

Type Values Removed Values Added
Title Out‑of‑Order Segment Reassembly Denial of Service in OCaml utcp

Wed, 09 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Description An issue was discovered in the utcp package before 0.0.6 for OCaml. Out-of-order segment reassembly allows remote denial of service.
Weaknesses CWE-923
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-14T12:57:32.352Z

Reserved: 2026-09-09T04:13:54.781Z

Link: CVE-2026-87734

cve-icon Vulnrichment

Updated: 2026-09-14T12:57:24.051Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T05:18:20.577

Modified: 2026-09-14T13:19:00.020

Link: CVE-2026-87734

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:02:33Z

Weaknesses
  • CWE-923

    Improper Restriction of Communication Channel to Intended Endpoints