{"id":"MGASA-2026-0470","summary":"Updated tesseract packages fix security vulnerabilities","details":"This is a security update. It fixes nine vulnerabilities in tesseract,\nthe OCR (text recognition) engine. All nine can be triggered only by\nfeeding tesseract a maliciously crafted input file: either a specially\ncrafted recognition/language data file (.traineddata) or a crafted\nword-list file. Depending on the specific flaw, this can cause a crash\n(denial of service) or memory corruption.\n  CVE-2026-73067: out-of-bounds read when loading a crafted word-list\n                  file.\n  CVE-2026-73066: out-of-bounds write when loading a crafted\n                  recognition model file.\n  CVE-2026-88047: stack buffer overflow when loading a crafted\n                  language-normalisation file.\n  CVE-2026-88048: out-of-bounds read/write from a crafted neural-network\n                  layer in a recognition model file.\n  CVE-2026-88049: out-of-bounds write from a crafted neural-network\n                  layer in a recognition model file.\n  CVE-2026-88050: out-of-bounds write from invalid character-encoding\n                  values in a crafted recognition model file.\n  CVE-2026-88051: out-of-bounds write when loading a malformed internal\n                  data structure from a crafted recognition model file.\n  CVE-2026-88052: out-of-bounds write when loading a crafted\n                  character-set file.\n  CVE-2026-88053: out-of-bounds write when loading a crafted legacy\n                  recognition template file.\n  CVE-2026-88054: crash (denial of service) when loading a crafted\n                  recognition model with an empty internal network.\nThe tesseract package is updated to version 5.5.3, which on its own\nfixes CVE-2026-73067 and CVE-2026-73066. The remaining seven issues\n(CVE-2026-88047 to CVE-2026-88054) are not yet fixed in any upstream\nrelease, so nine patches taken from upstream's main development branch\nare also applied.\nReported by Tristan Madani (CVE-2026-88047) and Zhixi \"Jace\" Sun\n(CVE-2026-88048 to CVE-2026-88054); see the individual advisories below\nfor full credits, including CVE-2026-73067 and CVE-2026-73066.\n","modified":"2026-10-07T17:23:04.415485010Z","published":"2026-10-07T17:19:47Z","upstream":["CVE-2026-73067","CVE-2026-88047","CVE-2026-88048","CVE-2026-88049","CVE-2026-88050","CVE-2026-88051","CVE-2026-88052","CVE-2026-88053","CVE-2026-88054"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2026-0470.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=36427"},{"type":"WEB","url":"https://github.com/tesseract-ocr/tesseract/releases/tag/5.5.3"},{"type":"WEB","url":"https://osv.dev/vulnerability/openSUSE-SU-2026:21957-1"},{"type":"WEB","url":"https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/25OCRCHOE46S5WTJZC25DVGO7KC2KVWO/"},{"type":"ADVISORY","url":"https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-x3vq-7rr7-5x3h"},{"type":"WEB","url":"https://github.com/tesseract-ocr/tesseract/pull/4581"},{"type":"ADVISORY","url":"https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-7j76-5rq5-5jg8"},{"type":"WEB","url":"https://github.com/tesseract-ocr/tesseract/pull/4588"},{"type":"ADVISORY","url":"https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-5j2p-r5vc-q7f3"},{"type":"ADVISORY","url":"https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-q44c-23p6-5mw6"},{"type":"ADVISORY","url":"https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-jgq8-pprg-vc68"},{"type":"ADVISORY","url":"https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-7v9h-3q3m-w68g"},{"type":"ADVISORY","url":"https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-88qp-4g94-3rf3"},{"type":"ADVISORY","url":"https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-2hm8-q5c7-c373"},{"type":"ADVISORY","url":"https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-rphx-x795-5qjv"},{"type":"ADVISORY","url":"https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-f6h7-cqr4-6fx4"}],"affected":[{"package":{"name":"tesseract","ecosystem":"Mageia:10","purl":"pkg:rpm/mageia/tesseract?arch=source&distro=mageia-10"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.5.3-1.mga10"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2026-0470.json"}}],"schema_version":"1.9.0","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}