Home / mailings [USN-8882-1] Tesseract vulnerabilities
Posted on 06 October 2026
Ubuntu Security==========================================================================Ubuntu Security Notice USN-8882-1
October 06, 2026
tesseract vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS
Summary:
Several security issues were fixed in Tesseract.
Software Description:
- tesseract: OCR engine
Details:
It was discovered that Tesseract incorrectly handled crafted .traineddata
models. An attacker could possibly use this issue to cause Tesseract to
crash, resulting in a denial of service. (CVE-2026-73067)
It was discovered that Tesseract did not properly validate dimensions in
crafted .traineddata models. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-73066)
It was discovered that Tesseract did not properly limit token lengths in
crafted .traineddata models. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-88047)
It was discovered that Tesseract did not properly validate layer dimensions
in crafted .traineddata models. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-88048)
It was discovered that Tesseract did not properly validate layer sizes in
crafted .traineddata models. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-88049)
It was discovered that Tesseract incorrectly handled negative character
codes in crafted .traineddata models. An attacker could possibly use this
issue to cause Tesseract to crash, resulting in a denial of service.
(CVE-2026-88050)
It was discovered that Tesseract did not properly validate vector sizes in
crafted .traineddata models. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-88051)
It was discovered that Tesseract did not properly validate character IDs in
crafted .traineddata models. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-88052)
It was discovered that Tesseract did not properly validate classifier
counts in crafted .traineddata models. An attacker could possibly use this
issue to execute arbitrary code. (CVE-2026-88053)
It was discovered that Tesseract incorrectly handled empty network layers
in crafted .traineddata models. An attacker could possibly use this issue to
cause Tesseract to crash, resulting in a denial of service.
(CVE-2026-88054)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 26.04 LTS
libtesseract5 5.5.0-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 24.04 LTS
libtesseract5 5.3.4-1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 22.04 LTS
libtesseract4 4.1.1-2.1ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 20.04 LTS
libtesseract4 4.1.1-2ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 18.04 LTS
libtesseract4 4.00~git2288-10f4998a-2ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 16.04 LTS
libtesseract3 3.04.01-4ubuntu0.1~esm1
Available with Ubuntu Pro
Ubuntu 14.04 LTS
libtesseract3 3.04.01-4ubuntu0.1~esm1
Available with Ubuntu Pro
In general, a standard system update will make all the necessary changes.
References:
https://ubuntu.com/security/notices/USN-8882-1
CVE-2026-73066, CVE-2026-73067, CVE-2026-88047, CVE-2026-88048,
CVE-2026-88049, CVE-2026-88050, CVE-2026-88051, CVE-2026-88052,
CVE-2026-88053, CVE-2026-88054
--===============7067126002518968810==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature
