Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-54559— PocketSphinx: Buffer overflows in language and acoustic model loading code

Quick assessment

Affected
cmusphinx pocketsphinx
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

PocketSphinx 是一个小型语音识别器。在 5.1.1 版本之前,位于 中的三元组(Trie)语言模型加载器未充分验证 ARPA、DMP 及二进制格式文件头中的边界条件;此外,位于 和 中的声学模型加载器使用了未设置长度限制的 字符串字段。因此,加载无效、损坏或恶意的语言模型或声学模型可能导致栈或堆缓冲区溢出以及内存损坏。 能够向由 指定的目录进行写操作的攻击者,可以替换或添加 PocketSphinx 后续会加载的模型文件。使用 PocketSphinx 5prealpha 版本的用户没有可用的回移补丁,

CVSS 6.9 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-54559

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PocketSphinx: Buffer overflows in language and acoustic model loading code
Source: CVE Program / CVE List V5
Vulnerability Description
PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model loaders in src/mdef.c and src/util/bio.c use sscanf with unbounded string fields. Loading an invalid, corrupted, or malicious language or acoustic model can therefore cause stack or heap buffer overflows and memory corruption. An attacker who can write to a directory selected by POCKETSPHINX_PATH can replace or add a model file that PocketSphinx later loads; users of PocketSphinx 5prealpha have no backported patch and must migrate to the fixed release. This issue is fixed in version 5.1.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
内存缓冲区边界内操作的限制不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
cmusphinx pocketsphinx < 5.1.1 -

II. Public POCs for CVE-2026-54559

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-54559

登录查看更多情报信息。

Patches & Fixes for CVE-2026-54559 (2)

Vendor Advisories for CVE-2026-54559 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-54559

No comments yet


Leave a comment