Tesseract 是一个开源的 OCR(光学字符识别)引擎。在 5.5.3 及更早版本中, 中的 函数虽然会拒绝过大的网络堆栈,但却允许在构造的 模型中, 、 或 层出现零长度的堆栈。 在 中初始化 LSTMRecognizer 时, 会调用 中的 ,该函数会访问空向量中的 ,并通过一个无效的 Network 指针调用虚方法。这会导致在加载模型时发生确定性的崩溃和拒绝服务(DoS)。截至本次审查,尚无修复版本发布。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| tesseract-ocr | tesseract | <= 5.5.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-88049 | 8.6 HIGH | Tesseract: Heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatc |
| CVE-2026-88048 | 8.6 HIGH | Tesseract: Heap out-of-bounds write/read in FullyConnected::Forward via layer/weight-matri |
| CVE-2026-88047 | 8.6 HIGH | Tesseract: ReadNormProtos stack buffer overflow |
| CVE-2026-88051 | 8.6 HIGH | Tesseract: Heap out-of-bounds write in GenericVector<T>::read due to independent reserved/ |
| CVE-2026-88053 | 8.6 HIGH | Tesseract: Heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts i |
| CVE-2026-88052 | 7.8 HIGH | Tesseract: Heap out-of-bounds write in UNICHARSET::load_via_fgets via count/insert desynch |
| CVE-2026-88050 | 6.9 MEDIUM | Tesseract: Out-of-bounds write in UnicharCompress via unvalidated recoder code values |
No comments yet