Advisories ยป MGASA-2026-0470

Updated tesseract packages fix security vulnerabilities

Publication date: 07 Oct 2026
Modification date: 07 Oct 2026
Type: security
Affected Mageia releases : 10
CVE: CVE-2026-73067 , CVE-2026-88047 , CVE-2026-88048 , CVE-2026-88049 , CVE-2026-88050 , CVE-2026-88051 , CVE-2026-88052 , CVE-2026-88053 , CVE-2026-88054

Description

This is a security update. It fixes nine vulnerabilities in tesseract,
the OCR (text recognition) engine. All nine can be triggered only by
feeding tesseract a maliciously crafted input file: either a specially
crafted recognition/language data file (.traineddata) or a crafted
word-list file. Depending on the specific flaw, this can cause a crash
(denial of service) or memory corruption.
  CVE-2026-73067: out-of-bounds read when loading a crafted word-list
                  file.
  CVE-2026-73066: out-of-bounds write when loading a crafted
                  recognition model file.
  CVE-2026-88047: stack buffer overflow when loading a crafted
                  language-normalisation file.
  CVE-2026-88048: out-of-bounds read/write from a crafted neural-network
                  layer in a recognition model file.
  CVE-2026-88049: out-of-bounds write from a crafted neural-network
                  layer in a recognition model file.
  CVE-2026-88050: out-of-bounds write from invalid character-encoding
                  values in a crafted recognition model file.
  CVE-2026-88051: out-of-bounds write when loading a malformed internal
                  data structure from a crafted recognition model file.
  CVE-2026-88052: out-of-bounds write when loading a crafted
                  character-set file.
  CVE-2026-88053: out-of-bounds write when loading a crafted legacy
                  recognition template file.
  CVE-2026-88054: crash (denial of service) when loading a crafted
                  recognition model with an empty internal network.
The tesseract package is updated to version 5.5.3, which on its own
fixes CVE-2026-73067 and CVE-2026-73066. The remaining seven issues
(CVE-2026-88047 to CVE-2026-88054) are not yet fixed in any upstream
release, so nine patches taken from upstream's main development branch
are also applied.
Reported by Tristan Madani (CVE-2026-88047) and Zhixi "Jace" Sun
(CVE-2026-88048 to CVE-2026-88054); see the individual advisories below
for full credits, including CVE-2026-73067 and CVE-2026-73066.
                

References

SRPMS

10/core