Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-88052

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_insert_backwards_compatible can leave the vector unchanged for an empty, duplicate, or already-encodable representation, causing id to become larger than unichars.size(). Subsequent set_* calls and the write to unichars[id].properties.enabled then write UNICHAR_PROPERTIES beyond the vector during initialization in both the default LSTM and legacy engines, causing heap corruption, a crash, or potentially controlled corruption. No fixed release is available as of this review.

A flaw was found in Tesseract, an open-source Optical Character Recognition (OCR) engine. The UNICHARSET::load_via_fgets function incorrectly trusts a declared character count, which can lead to an out-of-bounds write in memory. A remote attacker could exploit this vulnerability by providing a specially crafted input, potentially causing heap corruption, a denial of service, or arbitrary code execution.

Меры по смягчению последствий

To mitigate this vulnerability, avoid processing untrusted or malicious image and document files with Tesseract. If Tesseract is not essential for system operations, consider removing the tesseract package to eliminate the attack surface. If the tesseract package is removed, ensure that any dependent applications or services are not adversely affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tesseractAffected
Red Hat Enterprise Linux 8tesseractAffected
Red Hat Enterprise Linux 9tesseractAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2531579tesseract: Tesseract: Heap out-of-bounds write can lead to arbitrary code execution

EPSS

Процентиль: 2%
0.00118
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
5 дней назад

(Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...)

CVSS3: 7.8
nvd
5 дней назад

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, UNICHARSET::load_via_fgets in src/ccutil/unicharset.cpp trusts the declared unichar count as a loop bound and uses id as an unchecked index into the unichars vector. unichar_insert_backwards_compatible can leave the vector unchanged for an empty, duplicate, or already-encodable representation, causing id to become larger than unichars.size(). Subsequent set_* calls and the write to unichars[id].properties.enabled then write UNICHAR_PROPERTIES beyond the vector during initialization in both the default LSTM and legacy engines, causing heap corruption, a crash, or potentially controlled corruption. No fixed release is available as of this review.

CVSS3: 7.8
debian
5 дней назад

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...

EPSS

Процентиль: 2%
0.00118
Низкий

7.8 High

CVSS3