Impact The trie language model code introduced in PocketSphinx 5prealpha failed to check various boundary conditions when reading the headers of ARPA, DMP, and binary format language model files. In the case of invalid,…
| CVE ID | CVE-2026-54559 |
| Vendor | Unknown Vendor |
| Affected Product | Unknown Product |
| Vulnerability Type | Security Vulnerability |
| CVSS Score | 5.5 (MEDIUM) |
| Actively Exploited | ❌ No known exploitation |
| Patch Status | Pending Vendor Disclosure |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex) |
#
The trie language model code introduced in PocketSphinx 5prealpha failed to check various boundary conditions when reading the headers of ARPA, DMP, and binary format language model files. In the case of invalid, corrupted or malicious input files, this could lead to stack and heap buffer overflows.
In addition, the acoustic model loading code (which is over 30 years old...) contains numerous instances of sscanf with an unbounded string field which could also lead to stack overflows in the case of corrupt or malicious inputs.
Because PocketSphinx will search the directory given by the POCKETSPHINX_PATH environment variable for acoustic and language model files, if this directory is writable by untrusted users, an attacker could corrupt an existing file or write a malicio
Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.