Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-88048

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions. During FullyConnected::Forward, MatrixDotVector in src/lstm/weightmatrix.cpp writes w.dim1() results into temp_line, which is sized from no_, and reads w.dim2() minus one inputs from curr_input, which is sized from ni_. A crafted .traineddata NT_SOFTMAX layer can therefore use inconsistent dimensions to cause a heap out-of-bounds write and read on the default LSTM engine, resulting in heap corruption, a crash, information disclosure, or potentially controlled corruption. No fixed release is available as of this review.

A flaw was found in Tesseract. The FullyConnected::DeSerialize function does not properly validate the dimensions of deserialized layers against the weight-matrix dimensions. This vulnerability allows a remote attacker to provide a specially crafted .traineddata file, leading to a heap out-of-bounds write and read during the FullyConnected::Forward operation. Successful exploitation can result in heap corruption, application crashes, or information disclosure.

Меры по смягчению последствий

To mitigate this issue, ensure that applications utilizing Tesseract only process .traineddata files from trusted and verified sources. Avoid processing .traineddata files obtained from untrusted or external origins.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tesseractAffected
Red Hat Enterprise Linux 8tesseractAffected
Red Hat Enterprise Linux 9tesseractAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2531546tesseract: Tesseract: Heap out-of-bounds write/read leading to information disclosure via crafted data

EPSS

Процентиль: 3%
0.0013
Низкий

7.8 High

CVSS3

Связанные уязвимости

ubuntu
5 дней назад

(Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...)

nvd
5 дней назад

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, FullyConnected::DeSerialize in src/lstm/fullyconnected.cpp does not validate the deserialized layer scalars ni_ and no_ against the weight-matrix dimensions. During FullyConnected::Forward, MatrixDotVector in src/lstm/weightmatrix.cpp writes w.dim1() results into temp_line, which is sized from no_, and reads w.dim2() minus one inputs from curr_input, which is sized from ni_. A crafted .traineddata NT_SOFTMAX layer can therefore use inconsistent dimensions to cause a heap out-of-bounds write and read on the default LSTM engine, resulting in heap corruption, a crash, information disclosure, or potentially controlled corruption. No fixed release is available as of this review.

debian
5 дней назад

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...

EPSS

Процентиль: 3%
0.0013
Низкий

7.8 High

CVSS3