Tesseract 是一个开源的 OCR(光学字符识别)引擎。在 5.5.3 及更早版本中, 中的 函数在解析 文件的 组件时,使用 将以空白符分隔的 token 提取到一个固定的 61 字节栈缓冲区中,但未设置流宽(stream width)。由于 100 字节的行缓冲区可承载最长 99 个字符的 token,若 token 长度超过 60 个字符,在 legacy 引擎的 阶段,最多会有 39 个攻击者可控的字节写入缓冲区之外,导致栈内存损坏、服务拒绝(DoS),并在受影响的 C++ 标准库实现中可能导致控制流
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tesseract-ocr | tesseract | <= 5.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88049 | 8.6 HIGH | Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatc |
| CVE-2026-88048 | 8.6 HIGH | Tesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matri |
| CVE-2026-88051 | 8.6 HIGH | Tesseract: Heap out-of-bounds write in GenericVector<T>::read due to independent reserved/ |
| CVE-2026-88053 | 8.6 HIGH | Tesseract: Heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts i |
| CVE-2026-88052 | 7.8 HIGH | Tesseract: Heap out-of-bounds write in UNICHARSET::load_via_fgets via count/insert desynch |
| CVE-2026-88050 | 6.9 MEDIUM | Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values |
| CVE-2026-88054 | 6.9 MEDIUM | Tesseract: Denial of service via empty-stack dereference in Plumbing/Series at model load |
No comments yet