Skip to content
VulniPulse
Highest advisory severityHigh 1 vendor · 1 advisory

CVE-2026-73066

CVE-2026-73066: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.

Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.

Vendor advisory comparison

Red Hat

1 advisory
  • Advisory severityHigh7.1

    High [CVE-2026-73066] Heap out-of-bounds write via crafted.traineddata

    CVE-2026-73066Source published Source updated

    Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted.traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3. A remote attacker could exploit this by providing a specially crafted.traineddata LSTM model component. This vulnerability could result in a denial of service or potentially arbitrary code execution. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H). Weakness: CWE-787.

    Affected products in this advisory
    • Red Hat Enterprise Linux 10.0 Extended Update Support
    • Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
    • Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
    • Red Hat Enterprise Linux 8.8 Telecommunications Update Service

    9 more entries in the full advisory.

    Source-reported affected versions
    • < 5.5.3
    Source-reported fixed versions
    • 5.5.3
    • tesseract-0:5.3.4-7.el10_2
    • tesseract-0:5.3.4-6.el10_0.1
    • tesseract-0:4.1.1-3.el8_10

    46 more entries in the full advisory.

    Mitigation guidance
    • To mitigate this issue, avoid processing `.traineddata` files from untrusted sources with Tesseract. Ensure that only `.traineddata` files from known, reputable origins are used for OCR recognition.

Android app · Google Play

Monitor future Red Hat CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery