Updated tesseract packages fix security vulnerabilities
Publication date: 07 Oct 2026Modification date: 07 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-73067 , CVE-2026-88047 , CVE-2026-88048 , CVE-2026-88049 , CVE-2026-88050 , CVE-2026-88051 , CVE-2026-88052 , CVE-2026-88053 , CVE-2026-88054
Description
This is a security update. It fixes nine vulnerabilities in tesseract,
the OCR (text recognition) engine. All nine can be triggered only by
feeding tesseract a maliciously crafted input file: either a specially
crafted recognition/language data file (.traineddata) or a crafted
word-list file. Depending on the specific flaw, this can cause a crash
(denial of service) or memory corruption.
CVE-2026-73067: out-of-bounds read when loading a crafted word-list
file.
CVE-2026-73066: out-of-bounds write when loading a crafted
recognition model file.
CVE-2026-88047: stack buffer overflow when loading a crafted
language-normalisation file.
CVE-2026-88048: out-of-bounds read/write from a crafted neural-network
layer in a recognition model file.
CVE-2026-88049: out-of-bounds write from a crafted neural-network
layer in a recognition model file.
CVE-2026-88050: out-of-bounds write from invalid character-encoding
values in a crafted recognition model file.
CVE-2026-88051: out-of-bounds write when loading a malformed internal
data structure from a crafted recognition model file.
CVE-2026-88052: out-of-bounds write when loading a crafted
character-set file.
CVE-2026-88053: out-of-bounds write when loading a crafted legacy
recognition template file.
CVE-2026-88054: crash (denial of service) when loading a crafted
recognition model with an empty internal network.
The tesseract package is updated to version 5.5.3, which on its own
fixes CVE-2026-73067 and CVE-2026-73066. The remaining seven issues
(CVE-2026-88047 to CVE-2026-88054) are not yet fixed in any upstream
release, so nine patches taken from upstream's main development branch
are also applied.
Reported by Tristan Madani (CVE-2026-88047) and Zhixi "Jace" Sun
(CVE-2026-88048 to CVE-2026-88054); see the individual advisories below
for full credits, including CVE-2026-73067 and CVE-2026-73066.
References
- https://bugs.mageia.org/show_bug.cgi?id=36427
- https://github.com/tesseract-ocr/tesseract/releases/tag/5.5.3
- https://osv.dev/vulnerability/openSUSE-SU-2026:21957-1
- https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/message/25OCRCHOE46S5WTJZC25DVGO7KC2KVWO/
- https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-x3vq-7rr7-5x3h
- https://github.com/tesseract-ocr/tesseract/pull/4581
- https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-7j76-5rq5-5jg8
- https://github.com/tesseract-ocr/tesseract/pull/4588
- https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-5j2p-r5vc-q7f3
- https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-q44c-23p6-5mw6
- https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-jgq8-pprg-vc68
- https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-7v9h-3q3m-w68g
- https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-88qp-4g94-3rf3
- https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-2hm8-q5c7-c373
- https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-rphx-x795-5qjv
- https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-f6h7-cqr4-6fx4
- https://www.cve.org/CVERecord?id=CVE-2026-73067
- https://www.cve.org/CVERecord?id=CVE-2026-88047
- https://www.cve.org/CVERecord?id=CVE-2026-88048
- https://www.cve.org/CVERecord?id=CVE-2026-88049
- https://www.cve.org/CVERecord?id=CVE-2026-88050
- https://www.cve.org/CVERecord?id=CVE-2026-88051
- https://www.cve.org/CVERecord?id=CVE-2026-88052
- https://www.cve.org/CVERecord?id=CVE-2026-88053
- https://www.cve.org/CVERecord?id=CVE-2026-88054
SRPMS
10/core
- tesseract-5.5.3-1.mga10