Security update for tesseract-ocr
A security update for tesseract-ocr addresses multiple vulnerabilities including heap out-of-bounds reads and writes, stack buffer overflow, and denial of service via empty-stack dereference. These issues arise from crafted models or trained data causing memory corruption or crashes. The update synchronizes tesseract-ocr to version 5.5.3, which fixes these flaws.
AI Analysis
Technical Summary
The tesseract-ocr update to version 5.5.3 fixes several security issues: CVE-2026-73067 involves a heap out-of-bounds read in SquishedDawg triggered by crafted models; CVE-2026-88047 is a stack buffer overflow in Classify::ReadNormProtos from crafted traineddata; CVE-2026-88048 and CVE-2026-88049 are heap out-of-bounds write/read errors caused by dimension mismatches in FullyConnected::Forward and LSTM::Forward respectively; CVE-2026-88050 involves out-of-bounds writes due to unvalidated recoder code values in UnicharCompress; CVE-2026-88051 and CVE-2026-88052 are heap out-of-bounds writes related to GenericVector<T>::read and UNICHARSET::load_via_fgets due to count or size desynchronizations; CVE-2026-88053 is a heap out-of-bounds write in Classify::ReadIntTemplates from unvalidated counts in crafted traineddata; CVE-2026-88054 causes denial of service via empty-stack dereference at model load. These vulnerabilities can lead to memory corruption or crashes when processing maliciously crafted OCR models or data.
Potential Impact
These vulnerabilities can cause memory corruption including out-of-bounds reads and writes, stack buffer overflows, and denial of service conditions. Exploitation could lead to application crashes or potentially arbitrary code execution depending on the context, though no known exploits are reported. The flaws arise from improper validation of crafted OCR models and trained data inputs.
Mitigation Recommendations
Update tesseract-ocr to version 5.5.3 or later, which includes fixes for all listed vulnerabilities. No additional mitigation is required once the update is applied.
Security update for tesseract-ocr
Description
A security update for tesseract-ocr addresses multiple vulnerabilities including heap out-of-bounds reads and writes, stack buffer overflow, and denial of service via empty-stack dereference. These issues arise from crafted models or trained data causing memory corruption or crashes. The update synchronizes tesseract-ocr to version 5.5.3, which fixes these flaws.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The tesseract-ocr update to version 5.5.3 fixes several security issues: CVE-2026-73067 involves a heap out-of-bounds read in SquishedDawg triggered by crafted models; CVE-2026-88047 is a stack buffer overflow in Classify::ReadNormProtos from crafted traineddata; CVE-2026-88048 and CVE-2026-88049 are heap out-of-bounds write/read errors caused by dimension mismatches in FullyConnected::Forward and LSTM::Forward respectively; CVE-2026-88050 involves out-of-bounds writes due to unvalidated recoder code values in UnicharCompress; CVE-2026-88051 and CVE-2026-88052 are heap out-of-bounds writes related to GenericVector<T>::read and UNICHARSET::load_via_fgets due to count or size desynchronizations; CVE-2026-88053 is a heap out-of-bounds write in Classify::ReadIntTemplates from unvalidated counts in crafted traineddata; CVE-2026-88054 causes denial of service via empty-stack dereference at model load. These vulnerabilities can lead to memory corruption or crashes when processing maliciously crafted OCR models or data.
Potential Impact
These vulnerabilities can cause memory corruption including out-of-bounds reads and writes, stack buffer overflows, and denial of service conditions. Exploitation could lead to application crashes or potentially arbitrary code execution depending on the context, though no known exploits are reported. The flaws arise from improper validation of crafted OCR models and trained data inputs.
Mitigation Recommendations
Update tesseract-ocr to version 5.5.3 or later, which includes fixes for all listed vulnerabilities. No additional mitigation is required once the update is applied.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- SUSE Product Security Team
- Advisory Id
- openSUSE-SU-2026:21957-1
- Cve Count
- 9
- Additional Cves
- ["CVE-2026-88047","CVE-2026-88048","CVE-2026-88049","CVE-2026-88050","CVE-2026-88051","CVE-2026-88052","CVE-2026-88053","CVE-2026-88054"]
- State
- PUBLISHED
Threat ID: 6abeb3f5a43b0b3b89ed4858
Added to database: 10/01/2026, 19:26:45 UTC
Last enriched: 10/01/2026, 19:35:15 UTC
Last updated: 10/02/2026, 18:57:15 UTC
Views: 18
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.