Home / mailingsPDF  

[USN-8882-1] Tesseract vulnerabilities

Posted on 06 October 2026
Ubuntu Security

==========================================================================Ubuntu Security Notice USN-8882-1
October 06, 2026

tesseract vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS
- Ubuntu 20.04 LTS
- Ubuntu 18.04 LTS
- Ubuntu 16.04 LTS
- Ubuntu 14.04 LTS

Summary:

Several security issues were fixed in Tesseract.

Software Description:
- tesseract: OCR engine

Details:

It was discovered that Tesseract incorrectly handled crafted .traineddata
models. An attacker could possibly use this issue to cause Tesseract to
crash, resulting in a denial of service. (CVE-2026-73067)

It was discovered that Tesseract did not properly validate dimensions in
crafted .traineddata models. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-73066)

It was discovered that Tesseract did not properly limit token lengths in
crafted .traineddata models. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-88047)

It was discovered that Tesseract did not properly validate layer dimensions
in crafted .traineddata models. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-88048)

It was discovered that Tesseract did not properly validate layer sizes in
crafted .traineddata models. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-88049)

It was discovered that Tesseract incorrectly handled negative character
codes in crafted .traineddata models. An attacker could possibly use this
issue to cause Tesseract to crash, resulting in a denial of service.
(CVE-2026-88050)

It was discovered that Tesseract did not properly validate vector sizes in
crafted .traineddata models. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-88051)

It was discovered that Tesseract did not properly validate character IDs in
crafted .traineddata models. An attacker could possibly use this issue to
execute arbitrary code. (CVE-2026-88052)

It was discovered that Tesseract did not properly validate classifier
counts in crafted .traineddata models. An attacker could possibly use this
issue to execute arbitrary code. (CVE-2026-88053)

It was discovered that Tesseract incorrectly handled empty network layers
in crafted .traineddata models. An attacker could possibly use this issue to
cause Tesseract to crash, resulting in a denial of service.
(CVE-2026-88054)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
libtesseract5 5.5.0-1ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 24.04 LTS
libtesseract5 5.3.4-1ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 22.04 LTS
libtesseract4 4.1.1-2.1ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 20.04 LTS
libtesseract4 4.1.1-2ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 18.04 LTS
libtesseract4 4.00~git2288-10f4998a-2ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 16.04 LTS
libtesseract3 3.04.01-4ubuntu0.1~esm1
Available with Ubuntu Pro

Ubuntu 14.04 LTS
libtesseract3 3.04.01-4ubuntu0.1~esm1
Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
https://ubuntu.com/security/notices/USN-8882-1
CVE-2026-73066, CVE-2026-73067, CVE-2026-88047, CVE-2026-88048,
CVE-2026-88049, CVE-2026-88050, CVE-2026-88051, CVE-2026-88052,
CVE-2026-88053, CVE-2026-88054

--===============7067126002518968810==Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: OpenPGP digital signature

 

TOP