Impact
An undocumented exception is raised by the mirage-crypto-pk library when RSA decryption or encryption processes a very small message, and the library does not handle this exception, causing the calling application to abort or behave unpredictably; this flaw is identified as CWE‑1284 and manifests as a crash that can be leveraged for denial of service.
Affected Systems
The vulnerability affects the OCaml mirage-crypto-pk package for all releases prior to 2.3.0; any OCaml application or service that incorporates this library for RSA key operations is potentially exposed.
Risk and Exploitability
The CVSS score of 4.3 indicates low severity, and no EPSS data is available to assess exploitation probability; the vulnerability is not listed in CISA's KEV catalog. The most likely attack vector is local or requires an untrusted user to invoke RSA operations with a small message, which is feasible in environments with insufficient input validation; no known remote exploitation or data leakage is documented, so the risk remains limited to availability and stability.
OpenCVE Enrichment