Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-88054

Опубликовано: 10 сент. 2026
Источник: redhat
CVSS3: 5.5
EPSS Низкий

Описание

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or NT_REVERSED layers in a crafted .traineddata model. During LSTMRecognizer initialization in src/lstm/lstmrecognizer.cpp, CacheXScaleFactor(XScaleFactor()) reaches Series::CacheXScaleFactor in src/lstm/series.cpp, which dereferences stack_[0] on the empty vector and invokes a virtual method through an invalid Network pointer. This causes a deterministic crash and denial of service at model load. No fixed release is available as of this review.

A flaw was found in Tesseract, an open-source Optical Character Recognition (OCR) engine. A remote attacker could provide a specially crafted '.traineddata' model with a zero-length stack for certain internal layers. This would cause an empty-stack dereference during model loading, leading to a deterministic crash of the application. This vulnerability results in a Denial of Service (DoS).

Меры по смягчению последствий

To mitigate this issue, ensure that Tesseract only processes .traineddata models from trusted sources. Avoid loading or using models from untrusted or unverified origins. Additionally, consider running applications that utilize Tesseract in a sandboxed environment to limit the potential impact of a crash.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10tesseractFix deferred
Red Hat Enterprise Linux 8tesseractFix deferred
Red Hat Enterprise Linux 9tesseractFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2531576tesseract: Tesseract: Denial of Service via crafted model with empty stack dereference

EPSS

Процентиль: 7%
0.00175
Низкий

5.5 Medium

CVSS3

Связанные уязвимости

ubuntu
5 дней назад

(Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...)

nvd
5 дней назад

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Plumbing::DeSerialize in src/lstm/plumbing.cpp rejects excessively large network stacks but accepts a zero-length stack for NT_SERIES, NT_PARALLEL, or NT_REVERSED layers in a crafted .traineddata model. During LSTMRecognizer initialization in src/lstm/lstmrecognizer.cpp, CacheXScaleFactor(XScaleFactor()) reaches Series::CacheXScaleFactor in src/lstm/series.cpp, which dereferences stack_[0] on the empty vector and invokes a virtual method through an invalid Network pointer. This causes a deterministic crash and denial of service at model load. No fixed release is available as of this review.

debian
5 дней назад

Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...

EPSS

Процентиль: 7%
0.00175
Низкий

5.5 Medium

CVSS3