High [CVE-2026-73066] Heap out-of-bounds write via crafted.traineddata
This high-severity Red Hat Linux advisory covers CVE-2026-73066 affecting Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support, Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.
Summary
Tesseract is an open source OCR engine.
Prior to 5.5.3, a crafted.traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition.
This issue is fixed in version 5.5.3. A remote attacker could exploit this by providing a specially crafted.traineddata LSTM model component.
This vulnerability could result in a denial of service or potentially arbitrary code execution. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H).
Weakness: CWE-787.
Affected products named by the advisory: Red Hat Enterprise Linux 10.0 Extended Update Support; Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support; Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On; Red Hat Enterprise Linux 8.8 Telecommunications Update Service; and 9 more.
- < 5.5.3
Official advisory · high-confidence parse· fetched 9 days ago·verify at source
- 5.5.3
- tesseract-0:5.3.4-7.el10_2
- tesseract-0:5.3.4-6.el10_0.1
- tesseract-0:4.1.1-3.el8_10
- tesseract-0:4.1.1-2.el8_6.1
- tesseract-0:4.1.1-2.el8_8.1
- tesseract-0:4.1.1-8.el9_8
- tesseract-0:4.1.1-7.el9_2.1
- tesseract-0:4.1.1-7.el9_4.1
- tesseract-0:4.1.1-7.el9_6.1
- rhaiis/model-opt-cuda-rhel9:1790621714
- rhaiis/vllm-cuda-rhel9:1790621718
- rhaiis/vllm-rocm-rhel9:1790621713
- rhai/base-image-rocm-rhel9:1790276886
- rhai/base-image-tpu-rhel9:1790276884
- rhai/base-image-cpu-rhel9:1790277045
- rhai/base-image-spyre-rhel9:1790276889
- rhai/base-image-cuda-rhel9:1790276974
- rhai/base-image-tpu-rhel9:1790703497
- rhai/base-image-rocm-rhel9:1790703506
- rhai/base-image-cpu-rhel9:1790703590
- rhai/base-image-spyre-rhel9:1790703568
- rhai/base-image-cuda-rhel9:1790703586
- rhai/base-image-rocm-rhel9:1790703494
- rhai/base-image-cpu-rhel9:1790703615
- rhai/base-image-tpu-rhel9:1790703516
- rhai/base-image-rocm-6.4-rhel9:1790703524
- rhai/base-image-cuda-13.0-rhel9:1790703601
- rhai/base-image-rocm-7.0-rhel9:1790703516
- rhai/base-image-cuda-12.9-rhel9:1790703608
- rhai/base-image-spyre-rhel9:1790703579
- rhai/base-image-neuron-rhel9:1790703516
- RHSA-2026:67830
- RHSA-2026:71566
- RHSA-2026:67832
- RHSA-2026:69495
- RHSA-2026:69111
- RHSA-2026:67831
- RHSA-2026:72280
- RHSA-2026:71568
- RHSA-2026:71567
- RHSA-2026:73859
- RHSA-2026:73929
- RHSA-2026:73930
- RHSA-2026:73909
- RHSA-2026:73959
- RHSA-2026:73960
- RHSA-2026:73961
- RHSA-2026:73962
- RHSA-2026:74458
Official advisory · high-confidence parse· fetched 9 days ago·verify at source
Mitigation checklist
- To mitigate this issue, avoid processing `.traineddata` files from untrusted sources with Tesseract. Ensure that only `.traineddata` files from known, reputable origins are used for OCR recognition.
Official advisory · high-confidence parse· fetched 9 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.