PT-2026-60899 · Unknown · Pocketsphinx
CVE-2026-54559
·
Published
2026-07-17
·
Updated
2026-07-23
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PocketSphinx versions 5prealpha through 5.1.0
Description
The trie language model code fails to check boundary conditions when reading headers of ARPA, DMP, and binary format language model files, which can lead to stack and heap buffer overflows when processing invalid, corrupted, or malicious files. Additionally, the acoustic model loading code uses
sscanf() with unbounded string fields, potentially causing stack overflows. An attacker can trigger these issues by corrupting or placing malicious files in the directory specified by the POCKETSPHINX PATH environment variable if that directory is writable by untrusted users.Recommendations
Update to version 5.1.1.
Ensure that the
POCKETSPHINX PATH environment variable is either unset or set to a trusted directory that cannot be written to by untrusted users.Exploit
Fix
Stack Overflow
Heap Based Buffer Overflow
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pocketsphinx