Out-of-bounds write in tesseract - #VU140986
Published: August 5, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to out-of-bounds write in the LSTM Convolve layer when parsing a crafted .traineddata LSTM model component during ordinary OCR recognition. A remote attacker can supply a specially crafted .traineddata file to cause a denial of service.
The issue is triggered after the malicious model file is loaded through Tesseract's .traineddata deserializer.