GHSA-56r5-2p2f-7cxp: PocketSphinx: Buffer overflows in language and acoustic model loading code
Summary
PocketSphinx (a speech recognition library) versions up to 5prealpha have buffer overflow vulnerabilities (memory safety bugs where data overflows allocated memory boundaries) in code that reads language and acoustic model files. An attacker could exploit this by placing a malicious file in a directory specified by the POCKETSPHINX_PATH environment variable, especially if that directory is writable by untrusted users.
Solution / Mitigation
Update to PocketSphinx 5.1.1, which corrects the vulnerability. If updating is not immediately possible, ensure the POCKETSPHINX_PATH environment variable is either unset or points to a directory whose contents are trusted and cannot be written by untrusted users.
Vulnerability Details
EPSS: 0.0%
Yes
July 17, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
Original source: https://github.com/advisories/GHSA-56r5-2p2f-7cxp
First tracked: July 17, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 75%