CVE-2026-54559 with a CVSS score of 6.9 is a vulnerability in the PocketSphinx library, specifically in its language and acoustic model loading code, which can lead to stack and heap buffer overflows due to unchecked boundary conditions when reading headers of ARPA, DMP, and binary format language model files, as well as unbounded string fields in sscanf functions that could also result in stack overflows. An attacker with write access to the directory specified by the POCKETSPHINX_PATH environment variable can trigger this vulnerability by corrupting or writing a malicious file to the directory. The affected versions include all prior to 5.1.1, and users are advised to migrate as soon as possible to version 5.1.1 to prevent exploitation.
We recommend you to update PocketSphinx to version 5.1.1.[/subscribe_to_unlock_form]
CVE-2026-54559 with a CVSS score of 6.9 is a vulnerability in the PocketSphinx library, specifically in its language and acoustic model loading code, which can lead to stack and heap buffer overflows due to unchecked boundary conditions when reading headers of ARPA, DMP, and binary format language model files, as well as unbounded string fields in sscanf functions that could also result in stack overflows. An attacker with write access to the directory specified by the POCKETSPHINX_PATH environment variable can trigger this vulnerability by corrupting or writing a malicious file to the directory. The affected versions include all prior to 5.1.1, and users are advised to migrate as soon as possible to version 5.1.1 to prevent exploitation.
We recommend you to update PocketSphinx to version 5.1.1.[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]