Back

MEDIUM

Tesseract: Heap OOB read in the DAWG loader

Published Aug 11, 2026

Description

Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .traineddata model loaded through TessBaseAPI::Init can cause SquishedDawg::read_squished_dawg in src/dict/dawg.cpp to accept an unterminated forward-edge run, after which SquishedDawg::Load calls num_forward_edges(0) and last_edge in src/dict/dawg.h reads beyond edges_, causing a heap out-of-bounds read and process crash before image processing. This issue is fixed in version 5.5.3.

Affected products

Remediation

Red Hat statement

A flaw was found in Tesseract, an open-source Optical Character Recognition (OCR) engine. A heap out-of-bounds read in the DAWG dictionary loader can be triggered by a specially crafted .traineddata model file, causing the Tesseract process to crash. This issue requires a user to load an untrusted model file, limiting the attack surface.

Red Hat mitigation

Only use .traineddata model files obtained from trusted sources. Do not load model files from untrusted or unknown origins.

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Aug 11, 2026
Updated Aug 11, 2026
Reserved Aug 10, 2026
CISA Vulnrichment
Updated Aug 11, 2026
NVD
Status Deferred
Modified Sep 9, 2026
Red Hat
Severity Moderate
Public date Aug 11, 2026
ENISA EUVD
Assigner GitHub_M
Published Aug 11, 2026
Updated Aug 11, 2026
Exploited since n/a
EUVD-2026-56182