Description
PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model loaders in src/mdef.c and src/util/bio.c use sscanf with unbounded string fields. Loading an invalid, corrupted, or malicious language or acoustic model can therefore cause stack or heap buffer overflows and memory corruption. An attacker who can write to a directory selected by POCKETSPHINX_PATH can replace or add a model file that PocketSphinx later loads; users of PocketSphinx 5prealpha have no backported patch and must migrate to the fixed release. This issue is fixed in version 5.1.1.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Stack or heap buffer overflows that can lead to memory corruption
Action: Immediate Patch
AI Analysis

Impact

The problem lies in PocketSphinx’s language‑model and acoustic‑model loading routines, which do not properly validate boundary conditions when parsing ARPA, DMP, or binary format headers and rely on unbounded sscanf calls. Loading a crafted, corrupted, or malicious language or acoustic model can therefore trigger stack or heap buffer overflows, corrupting memory and potentially compromising process integrity. An attacker who can write to a directory specified by the POCKETSPHINX_PATH environment variable can replace or add a model file that PocketSphinx later loads, giving them the opportunity to supply a harmful model and trigger the overflow.

Affected Systems

All PocketSphinx distributions managed by the CMU Sphinx project that are older than version 5.1.1, including the 5prealpha branch, are affected. Users who run PocketSphinx from a directory selected by the POCKETSPHINX_PATH environment variable may be able to write will subsequently load.

Risk and Exploitability

The CVSS score is 6.9, indicating moderate severity. The EPSS score is < 1%, suggesting a very low but nonzero likelihood of exploitation. This vulnerability is not listed in the CISA KEV catalog. The primary attack surface is local file manipulation: an attacker with write access to the directory specified by POCKETSPHINX_PATH can replace or add a model file that PocketSphinx will subsequently load, potentially causing memory corruption. Remote exploitation would require a means to supply a malicious model file or influence the model path.

Generated by OpenCVE AI on September 20, 2026 at 22:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update PocketSphinx to version 5.1.1 or later, which includes the boundary checks and safe string handling for model files.
  • Restrict write permissions on the directory pointed to by POCKETSPHINX_PATH so that only trusted users or the application itself can modify model files; consider changing the path to a system‑controlled location with strict controls.
  • If an immediate update is not possible, remove or disable the POCKETSPHINX_PATH configuration and use only bundled or system‑wide model directories that are not writable by untrusted users.

Generated by OpenCVE AI on September 20, 2026 at 22:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-56r5-2p2f-7cxp PocketSphinx: Buffer overflows in language and acoustic model loading code
History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Cmusphinx
Cmusphinx pocketsphinx
Vendors & Products Cmusphinx
Cmusphinx pocketsphinx

Tue, 15 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description PocketSphinx is a small speech recognizer. Prior to 5.1.1, the trie language-model loaders in src/lm/ngram_model_trie.c do not adequately validate boundary conditions in ARPA, DMP, and binary format headers, and the acoustic-model loaders in src/mdef.c and src/util/bio.c use sscanf with unbounded string fields. Loading an invalid, corrupted, or malicious language or acoustic model can therefore cause stack or heap buffer overflows and memory corruption. An attacker who can write to a directory selected by POCKETSPHINX_PATH can replace or add a model file that PocketSphinx later loads; users of PocketSphinx 5prealpha have no backported patch and must migrate to the fixed release. This issue is fixed in version 5.1.1.
Title PocketSphinx: Buffer overflows in language and acoustic model loading code
Weaknesses CWE-119
CWE-121
CWE-122
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Cmusphinx Pocketsphinx
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-15T19:30:40.884Z

Reserved: 2026-06-15T19:04:14.457Z

Link: CVE-2026-54559

cve-icon Vulnrichment

Updated: 2026-09-15T19:30:35.859Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T20:16:46.573

Modified: 2026-09-30T17:51:36.337

Link: CVE-2026-54559

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T22:45:05Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-121

    Stack-based Buffer Overflow

  • CWE-122

    Heap-based Buffer Overflow