USN-8882-1: ten Tesseract flaws, some allow code execution
Ubuntu fixes ten CVEs in Tesseract linked to malicious .traineddata files: some allow arbitrary code execution.
UptimeMag editorial team · 6 October 2026 · 2 min read

Canonical published advisory USN-8882-1 on 6 October 2026, fixing ten vulnerabilities in Tesseract, the open-source OCR engine used in many document digitisation services and server-side text processing pipelines. This affects anyone with Tesseract installed as a dependency on Ubuntu machines, including indirectly via applications that perform optical character recognition.
According to the official Ubuntu advisory, all the issues stem from the handling of specially crafted .traineddata files: training models that Tesseract fails to validate correctly on several fronts (sizes, token lengths, layer dimensions, character codes, classifier counts, vector dimensions). Eight of the ten CVEs (including CVE-2026-73066, CVE-2026-88047, CVE-2026-88048, CVE-2026-88049, CVE-2026-88051, CVE-2026-88052, CVE-2026-88053) are classified as potentially allowing arbitrary code execution. The remaining two (CVE-2026-73067 and CVE-2026-88050) cause a crash, and therefore denial of service, the latter linked to the handling of negative character codes.
Packages and fixed versions
| Release | Package | Fixed version | Channel |
|---|---|---|---|
| 26.04 LTS (resolute) | libtesseract5 | 5.5.0-1ubuntu0.1~esm1 | Ubuntu Pro / ESM Apps |
| 24.04 LTS (noble) | libtesseract5 | 5.3.4-1ubuntu0.1~esm1 | Ubuntu Pro / ESM Apps |
| 22.04 LTS (jammy) | libtesseract4 | 4.1.1-2.1ubuntu0.1~esm1 | Ubuntu Pro / ESM Apps |
| 20.04 LTS (focal) | libtesseract4 | 4.1.1-2ubuntu0.1~esm1 | Ubuntu Pro / ESM Apps |
| 18.04 LTS (bionic) | libtesseract4 | 4.00 |
Ubuntu Pro / ESM Apps |
| 16.04 LTS (xenial) | libtesseract3 | 3.04.01-4ubuntu0.1~esm1 | ESM |
| 14.04 LTS (trusty) | libtesseract3 | 3.03.02-3ubuntu0.1~esm1 | Ubuntu Pro / Legacy Support add-on |
Source: official Ubuntu Security Notices advisory, USN-8882-1 (https://ubuntu.com/security/notices/USN-8882-1).
What to do
For all the releases listed, the fix requires Ubuntu Pro with ESM Apps enabled (or Legacy Support for 14.04); the advisory notes that a public fix may follow later for versions from 18.04 through to 26.04. Anyone running Tesseract in production to process documents uploaded by external users should treat this as a genuine risk: a malicious .traineddata file passed to the OCR engine can be enough to trigger the most serious flaws. Running sudo apt update && sudo apt upgrade with an active Ubuntu Pro subscription will apply the corrected packages.
Written with the help of artificial intelligence and checked by the editors (EU AI Act, art. 50). Source: Ubuntu – avvisi di sicurezza.