Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-88051— Tesseract: Heap out-of-bounds write in GenericVector<T>::read due to independent reserved/size_used_ fields

Quick assessment

Affected
tesseract-ocr tesseract
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Tesseract 是一个开源的光学字符识别(OCR)引擎。在 5.5.3 及更早版本中, 中 的回调形式在从 模型文件中读取独立的 字段 和 时,既没有设置上限,也没有进行不变量检查。调用 用于分配底层数组,但随后的回调循环会写入 个元素。因此,一个精心构造的 组件(其 为 4 或更高版本),当从 中调用 时,可以将 设置为一个较小的值,同时将 设置为一个较大的值,从而导致对 结构体发生堆越界写入、堆内存损坏、程序崩溃,甚至可能导致可控制的内存损坏。截至本次安全审查,尚未发布修复版本。

CVSS 8.6 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-88051

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Tesseract: Heap out-of-bounds write in GenericVector<T>::read due to independent reserved/size_used_ fields
Source: CVE Program / CVE List V5
Vulnerability Description
Tesseract is an open source OCR engine. In version 5.5.3 and earlier, the callback form of GenericVector::read in src/ccutil/genericvector.h reads the independent int32 fields reserved and size_used_ from a .traineddata model without a cap or an invariant check. reserve(reserved) allocates the backing array, but the callback loop writes size_used_ elements. A crafted TESSDATA_INTTEMP component with version_id 4 or later can therefore set reserved to a small value and size_used_ to a large value when fontinfo_table_.read(fp, read_info) is called from src/classify/intproto.cpp, causing a heap out-of-bounds write of FontInfo structures, heap corruption, a crash, or potentially controlled corruption. No fixed release is available as of this review.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
tesseract-ocr tesseract <= 5.5.3 -

II. Public POCs for CVE-2026-88051

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-88051

登录查看更多情报信息。

Patches & Fixes for CVE-2026-88051 (1)

Other References for CVE-2026-88051 (1)

Same Patch Batch · tesseract-ocr · 2026-09-10 · 8 CVEs total

CVE-2026-88049 8.6 HIGH Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatc
CVE-2026-88048 8.6 HIGH Tesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matri
CVE-2026-88047 8.6 HIGH Tesseract: ReadNormProtos stack buffer overflow
CVE-2026-88053 8.6 HIGH Tesseract: Heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts i
CVE-2026-88052 7.8 HIGH Tesseract: Heap out-of-bounds write in UNICHARSET::load_via_fgets via count/insert desynch
CVE-2026-88050 6.9 MEDIUM Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values
CVE-2026-88054 6.9 MEDIUM Tesseract: Denial of service via empty-stack dereference in Plumbing/Series at model load

IV. Related Vulnerabilities

V. Comments for CVE-2026-88051

No comments yet


Leave a comment