What is CVE-2026-73066?
In Tesseract versions prior to 5.5.3, a crafted LSTM model component loaded through the deserializer can trigger an unchecked signed integer multiplication in `Convolve::DeSerialize`, causing a wrap in the convolution output-channel count and leading to a potential security vulnerability. Affected users are advised to update to version 5.5.3 immediately.
Azərbaycanca: Tesseract-in 5.5.3 versiyasına qədər olan variantlarında, xüsusi hazırlanmış LSTM model komponenti yüklənərkən `Convolve::DeSerialize` funksiyasında işarəli tam ədəd vurması səbəbindən `output-channel` sayının səhv hesablanması nəticəsində təhlükəsizlik zəifliyi mövcuddur. Bu, uzaqdan kod icrasına yol aça bilər; təsirlənən istifadəçilər dərhal 5.5.3 versiyasına yeniləməlidir.
Related CVEs
link basis: same weakness class CWE-190
FAQ2
Which versions of Tesseract are affected by CVE-2026-73066?
Versions prior to 5.5.3 are affected.
What is the root cause of CVE-2026-73066?
An unchecked signed integer multiplication in Convolve::DeSerialize causes a wrap in the convolution output-channel count.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.