Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88047— Tesseract: ReadNormProtos stack buffer overflow

Quick assessment

Affected
tesseract-ocr tesseract
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Tesseract 是一个开源的 OCR(光学字符识别)引擎。在 5.5.3 及更早版本中, 中的 函数在解析 文件的 组件时,使用 将以空白符分隔的 token 提取到一个固定的 61 字节栈缓冲区中,但未设置流宽(stream width)。由于 100 字节的行缓冲区可承载最长 99 个字符的 token,若 token 长度超过 60 个字符,在 legacy 引擎的 阶段,最多会有 39 个攻击者可控的字节写入缓冲区之外,导致栈内存损坏、服务拒绝(DoS),并在受影响的 C++ 标准库实现中可能导致控制流

CVSS 8.6 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88047

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tesseract: ReadNormProtos stack buffer overflow
Source: CVE Program / CVE List V5
Vulnerability Description
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, Classify::ReadNormProtos in src/classify/normmatch.cpp parses the NORMPROTO component of a .traineddata file and uses std::istream::operator>>(char*) to extract a whitespace-delimited token into a fixed 61-byte stack buffer without setting a stream width. The 100-byte line buffer can carry a token of up to 99 characters, so a token longer than 60 characters writes up to 39 attacker-controlled bytes past the buffer during TessBaseAPI::Init of the legacy engine, causing stack corruption, denial of service, and potentially control-flow hijacking on affected standard-library implementations. Builds using Apple's libc++ C++20 bounded array overload are incidentally protected, while typical libstdc++ builds remain affected. No fixed release is available as of this review.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
栈缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
tesseract-ocr tesseract <= 5.5.3 -

II. Public POCs for CVE-2026-88047

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88047

登录查看更多情报信息。

Patches & Fixes for CVE-2026-88047 (1)

Vendor Advisories for CVE-2026-88047 (1)

Same Patch Batch · tesseract-ocr · 2026-09-10 · 8 CVEs total

CVE-2026-88049 8.6 HIGH Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatc
CVE-2026-88048 8.6 HIGH Tesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matri
CVE-2026-88051 8.6 HIGH Tesseract: Heap out-of-bounds write in GenericVector<T>::read due to independent reserved/
CVE-2026-88053 8.6 HIGH Tesseract: Heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts i
CVE-2026-88052 7.8 HIGH Tesseract: Heap out-of-bounds write in UNICHARSET::load_via_fgets via count/insert desynch
CVE-2026-88050 6.9 MEDIUM Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values
CVE-2026-88054 6.9 MEDIUM Tesseract: Denial of service via empty-stack dereference in Plumbing/Series at model load

IV. Related Vulnerabilities

V. Comments for CVE-2026-88047

No comments yet


Leave a comment