PT-2026-60899 · Unknown · Pocketsphinx

CVE-2026-54559

·

Published

2026-07-17

·

Updated

2026-07-23

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions PocketSphinx versions 5prealpha through 5.1.0
Description The trie language model code fails to check boundary conditions when reading headers of ARPA, DMP, and binary format language model files, which can lead to stack and heap buffer overflows when processing invalid, corrupted, or malicious files. Additionally, the acoustic model loading code uses sscanf() with unbounded string fields, potentially causing stack overflows. An attacker can trigger these issues by corrupting or placing malicious files in the directory specified by the POCKETSPHINX PATH environment variable if that directory is writable by untrusted users.
Recommendations Update to version 5.1.1. Ensure that the POCKETSPHINX PATH environment variable is either unset or set to a trusted directory that cannot be written to by untrusted users.

Exploit

Fix

Stack Overflow

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-54559
GHSA-56R5-2P2F-7CXP
PYSEC-2026-3498

Affected Products

Pocketsphinx