Impact
The problem lies in PocketSphinx’s language‑model and acoustic‑model loading routines, which do not properly validate boundary conditions when parsing ARPA, DMP, or binary format headers and rely on unbounded sscanf calls. Loading a crafted, corrupted, or malicious language or acoustic model can therefore trigger stack or heap buffer overflows, corrupting memory and potentially compromising process integrity. An attacker who can write to a directory specified by the POCKETSPHINX_PATH environment variable can replace or add a model file that PocketSphinx later loads, giving them the opportunity to supply a harmful model and trigger the overflow.
Affected Systems
All PocketSphinx distributions managed by the CMU Sphinx project that are older than version 5.1.1, including the 5prealpha branch, are affected. Users who run PocketSphinx from a directory selected by the POCKETSPHINX_PATH environment variable may be able to write will subsequently load.
Risk and Exploitability
The CVSS score is 6.9, indicating moderate severity. The EPSS score is < 1%, suggesting a very low but nonzero likelihood of exploitation. This vulnerability is not listed in the CISA KEV catalog. The primary attack surface is local file manipulation: an attacker with write access to the directory specified by POCKETSPHINX_PATH can replace or add a model file that PocketSphinx will subsequently load, potentially causing memory corruption. Remote exploitation would require a means to supply a malicious model file or influence the model path.
OpenCVE Enrichment
Github GHSA