Out-of-bounds read in tesseract - CVE-2026-73067
Published: August 5, 2026 / Updated: August 13, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds read in the DAWG dictionary loader when parsing a crafted .traineddata model file during initialization. A remote attacker can supply a specially crafted .traineddata model file to cause a denial of service.
The issue is triggered at model-load time before any image is processed.
Affected software
openEuler
tesseract
tesseract-tools
tesseract-devel
tesseract-debugsource
tesseract-debuginfo
How to mitigate CVE-2026-73067
tesseract - update to 5.5.3-1
tesseract-tools - update to 5.5.3-1
tesseract-devel - update to 5.5.3-1
tesseract-debugsource - update to 5.5.3-1
tesseract-debuginfo - update to 5.5.3-1