{"id":"CVE-2026-54559","summary":"PocketSphinx: Buffer overflows in language and acoustic model loading code","details":"PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model loaders in src/mdef.c and src/util/bio.c use sscanf with unbounded string fields. Loading an invalid, corrupted, or malicious language or acoustic model can therefore cause stack or heap buffer overflows and memory corruption. An attacker who can write to a directory selected by POCKETSPHINX_PATH can replace or add a model file that PocketSphinx later loads; users of PocketSphinx 5prealpha have no backported patch and must migrate to the fixed release. This issue is fixed in version 5.1.1.","aliases":["GHSA-56r5-2p2f-7cxp","PYSEC-2026-3498"],"modified":"2026-09-17T08:07:08.810172Z","published":"2026-09-14T20:07:50.850Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54559.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-119","CWE-121","CWE-122"]},"references":[{"type":"WEB","url":"https://github.com/cmusphinx/pocketsphinx/releases/tag/v5.1.1"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54559.json"},{"type":"ADVISORY","url":"https://github.com/cmusphinx/pocketsphinx/security/advisories/GHSA-56r5-2p2f-7cxp"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54559"},{"type":"FIX","url":"https://github.com/cmusphinx/pocketsphinx/commit/2a3c03788a9973eff548664334fb781e9f4ad4a5"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cmusphinx/pocketsphinx","events":[{"introduced":"0"},{"fixed":"2a3c03788a9973eff548664334fb781e9f4ad4a5"},{"fixed":"511126b492dcb267cf30d49d631946d7b61a9530"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"5.1.1"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["v5.1.0","v5.1.0rc2","v5.1.0rc1","v5.0.4","v5.0.3","v5.0.2","v5.0.1","v5.0.0","v5.0.0rc5","v5.0.0rc4","v5.0.0rc3","v5.0.0rc2","v5.0.0rc1","last-pre-1.0"],"database_specific":{"vanir_signatures":[{"digest":{"length":1309,"function_hash":"122103984833255382158286647859980188550"},"id":"CVE-2026-54559-0df7b34a","signature_type":"Function","signature_version":"v1","source":"https://github.com/cmusphinx/pocketsphinx/commit/2a3c03788a9973eff548664334fb781e9f4ad4a5","target":{"file":"src/mdef.c","function":"parse_tmat_senmap"},"deprecated":false},{"id":"CVE-2026-54559-1ec2de5f","signature_type":"Line","signature_version":"v1","source":"https://github.com/cmusphinx/pocketsphinx/commit/2a3c03788a9973eff548664334fb781e9f4ad4a5","target":{"file":"src/util/bio.c"},"deprecated":false,"digest":{"line_hashes":["106768376746432372306323753888382159193","251778364288489296810485811145953774952","175814721051340849214087665050445354196","78299399076821485733788188202283687440","283211298769510908202611514798591763211","98194435798881250100785024205230474752","217912592764658948860589287297515153893","166404067159499951133793025026932000101","172063095065143766620965858380588997115","232441402449377888605718358208852635777","235343383452874349980643774374129034890","291713633441843161630388993030792966530","206829567476674477166443354768929411936","245022165862453644897544921825211055576","11223783955570953557465563163368078765","328082160123395859040864608258865854006"],"threshold":0.9}},{"source":"https://github.com/cmusphinx/pocketsphinx/commit/2a3c03788a9973eff548664334fb781e9f4ad4a5","target":{"file":"src/mdef.c","function":"parse_tri_line"},"deprecated":false,"digest":{"length":1750,"function_hash":"267107659062547950832630460733762357272"},"id":"CVE-2026-54559-85e0159e","signature_type":"Function","signature_version":"v1"},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/cmusphinx/pocketsphinx/commit/2a3c03788a9973eff548664334fb781e9f4ad4a5","target":{"file":"src/util/bio.c","function":"bio_readhdr"},"deprecated":false,"digest":{"length":1734,"function_hash":"311797652281671942754591536490266574457"},"id":"CVE-2026-54559-892458bb"},{"signature_version":"v1","source":"https://github.com/cmusphinx/pocketsphinx/commit/2a3c03788a9973eff548664334fb781e9f4ad4a5","target":{"file":"src/mdef.c","function":"parse_base_line"},"deprecated":false,"digest":{"function_hash":"96099526088856950947547626631225905499","length":1124},"id":"CVE-2026-54559-95430350","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/cmusphinx/pocketsphinx/commit/2a3c03788a9973eff548664334fb781e9f4ad4a5","target":{"file":"src/mdef.c","function":"mdef_init"},"deprecated":false,"digest":{"function_hash":"251574157044833175737580087869665472407","length":4637},"id":"CVE-2026-54559-979afe9f","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/cmusphinx/pocketsphinx/commit/2a3c03788a9973eff548664334fb781e9f4ad4a5","target":{"file":"src/mdef.c"},"deprecated":false,"digest":{"line_hashes":["38400663645952544233054715977776912245","340118892623076776779007956647380601826","167473116211723438589807592413360288123","311833412677406993851836459763526732445","336263007992703572218705975973623860724","251117506222110130416025847399428130690","23919297133538049884199560396219563724","318515814483075186117997250471441976037","117808360833410720062246416782261041113","190446919108182897274055965544152578388","132140139406457282044193500409849452399","296744576221603543348798664491789830962","106841321285571755483411453112325951332","30640617070933735741497864936116699096","45041832189317990840613774520751406985","193857846509855978168744073057689969633","153630329379493993211280918783488217400","146992143470325373041051781897105273893","24286352189796245003665368247967634868","200267606543049472278227036098052064876","90976318775620354158141584547341143724","216248559722661298105478270465211655712","190446919108182897274055965544152578388","132140139406457282044193500409849452399","106594339922152068019292031455737277013","200965527671837038184697626321729770112","229828420380081903685833124521880518901","76619691586886626475257138038993129920","64405756660369526393203358402736864491","146539704126860798672029177343299860088","294745855454555806774753266522344471898","193373335903424604914148988097869960820","86237756600187618490620710513970387134","175789136790111804188304935666714004906","144121521081782811060069762632790407645","204814684528471745567028559496960644482","167275718901637269508916142192251262080","258610940877602281309951706423264512086","24286352189796245003665368247967634868","172582669801642947314328945521637798984","113910735417407631402077221370390071150","27448452989596827846262335183126164507","259121018305055163544932954698290486054","64937464737268733626799072606712031520"],"threshold":0.9},"id":"CVE-2026-54559-9a7f2b8e","signature_type":"Line"}],"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54559.json","vanir_signatures_modified":"2026-09-17T08:07:08Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"}]}