CVE-2026-73066
CVE-2026-73066: 1 tracked advisory record across Red Hat. Compare vendor sources and published fix guidance.
Compare the source-linked records below. Ratings and product/version details belong to each advisory; they are not a single CVE-wide score or proof that every listed product is affected. How VulniPulse collects and checks evidence.
Vendor advisory comparison
Red Hat
1 advisory- Advisory severityHigh7.1
High [CVE-2026-73066] Heap out-of-bounds write via crafted.traineddata
CVE-2026-73066Source published Source updated
Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted.traineddata LSTM model component loaded through Tesseract's deserializer can cause an unchecked signed integer multiplication in Convolve::DeSerialize in src/lstm/convolve.cpp to wrap the convolution output-channel count, undersizing the forward-pass output buffer while writes use the unwrapped element count and causing a heap out-of-bounds write during OCR recognition. This issue is fixed in version 5.5.3. A remote attacker could exploit this by providing a specially crafted.traineddata LSTM model component. This vulnerability could result in a denial of service or potentially arbitrary code execution. Red Hat severity: Important — CVSS 7.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:H). Weakness: CWE-787.
- Affected products in this advisory
- Red Hat Enterprise Linux 10.0 Extended Update Support
- Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
- Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On
- Red Hat Enterprise Linux 8.8 Telecommunications Update Service
9 more entries in the full advisory.
- Source-reported affected versions
- < 5.5.3
- Source-reported fixed versions
- 5.5.3
- tesseract-0:5.3.4-7.el10_2
- tesseract-0:5.3.4-6.el10_0.1
- tesseract-0:4.1.1-3.el8_10
46 more entries in the full advisory.
- Mitigation guidance
- To mitigate this issue, avoid processing `.traineddata` files from untrusted sources with Tesseract. Ensure that only `.traineddata` files from known, reputable origins are used for OCR recognition.
Android app · Google Play
Monitor future Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 34 official vendor sources and 160+ reviewed platform categories.