{"id":"openSUSE-SU-2026:21957-1","summary":"Security update for tesseract-ocr","details":"This update for tesseract-ocr fixes the following issues:\n\nChanges in tesseract-ocr:\n\n- Update to version 5.5.3 (sync with Factory):\n  * CVE-2026-73067: heap out-of-bounds read in SquishedDawg on crafted model (boo#1275623)\n  * CVE-2026-88047: stack buffer overflow in Classify::ReadNormProtos on crafted traineddata (boo#1280925)\n  * CVE-2026-88048: heap out-of-bounds write/read in FullyConnected::Forward via dimension mismatch (boo#1280929)\n  * CVE-2026-88049: heap out-of-bounds write in LSTM::Forward via na_/gate-matrix dimension mismatch (boo#1280930)\n  * CVE-2026-88050: out-of-bounds write in UnicharCompress via unvalidated recoder code values (boo#1280931)\n  * CVE-2026-88051: heap out-of-bounds write in GenericVector\u003cT\u003e::read via reserved/size_used_ mismatch\n    (boo#1280932)\n  * CVE-2026-88052: heap out-of-bounds write in UNICHARSET::load_via_fgets via count/insert\n    desynchronization (boo#1280933)\n  * CVE-2026-88053: heap out-of-bounds write in Classify::ReadIntTemplates via unvalidated counts in\n    crafted traineddata (boo#1280934)\n  * CVE-2026-88054: denial of service via empty-stack dereference at model load (boo#1280935)\n","modified":"2026-09-25T18:24:00.435764461Z","published":"2026-09-24T15:02:59Z","related":["CVE-2026-73067","CVE-2026-88047","CVE-2026-88048","CVE-2026-88049","CVE-2026-88050","CVE-2026-88051","CVE-2026-88052","CVE-2026-88053","CVE-2026-88054"],"upstream":["CVE-2026-73067","CVE-2026-88047","CVE-2026-88048","CVE-2026-88049","CVE-2026-88050","CVE-2026-88051","CVE-2026-88052","CVE-2026-88053","CVE-2026-88054"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1275623"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280925"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280929"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280930"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280931"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280932"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280933"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280934"},{"type":"REPORT","url":"https://bugzilla.suse.com/1280935"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-73067"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-88047"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-88048"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-88049"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-88050"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-88051"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-88052"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-88053"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-88054"}],"affected":[{"package":{"name":"tesseract-ocr","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/tesseract-ocr&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.5.3-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"tesseract-ocr-common":"5.5.3-bp160.1.1","tesseract-ocr-devel":"5.5.3-bp160.1.1","libtesseract5":"5.5.3-bp160.1.1","libtesseract5-x86-64-v3":"5.5.3-bp160.1.1","tesseract-ocr":"5.5.3-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21957-1.json"}}],"schema_version":"1.9.0"}