Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package tesseract-ocr for openSUSE:Factory checked in at 2026-09-30 16:21:56 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/tesseract-ocr (Old) and /work/SRC/openSUSE:Factory/.tesseract-ocr.new.1465845 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "tesseract-ocr" Wed Sep 30 16:21:56 2026 rev:27 rq:1381200 version:5.5.3 Changes: -------- --- /work/SRC/openSUSE:Factory/tesseract-ocr/tesseract-ocr.changes 2026-09-24 22:55:49.589114671 +0200 +++ /work/SRC/openSUSE:Factory/.tesseract-ocr.new.1465845/tesseract-ocr.changes 2026-09-30 16:22:45.415609662 +0200 @@ -1,0 +2,9 @@ +Mon Sep 28 15:07:02 UTC 2026 - Martin Pluskal <[email protected]> + +- Update tesseract-CVE-2026-88053.patch to null the adaptive + template pointer arrays again and the class pruners as + upstream does, fixing an abort at exit on every run and + invalid frees when a corrupt traineddata is rejected + (boo#1282863) + +------------------------------------------------------------------- ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ tesseract-CVE-2026-88053.patch ++++++ --- /var/tmp/diff_new_pack.ur9nmG/_old 2026-09-30 16:22:46.431652150 +0200 +++ /var/tmp/diff_new_pack.ur9nmG/_new 2026-09-30 16:22:46.434652275 +0200 @@ -42,6 +42,8 @@ # as bare pointers elsewhere (eg adaptmatch.cpp MasterMatcher call, # intproto.cpp AddIntProto loop). intproto.cpp ctor/dtor hunk replaced # with a minimal destructor loop-bound fix for the 5.5.3 code. +# adaptive.cpp ctors keep their explicit Config[]/Class[] nulling for the same reason. +# INT_TEMPLATES_STRUCT ctor nulls ClassPruners[] as upstream b27e1bd6 does (not in 5.5.3). # Makefile.am | 7 ++ src/ccmain/tessedit.cpp | 4 +- @@ -77,39 +79,7 @@ index e3297c0e0c..96850ab75b 100644 --- a/src/classify/adaptive.cpp +++ b/src/classify/adaptive.cpp -@@ -67,10 +67,6 @@ ADAPT_CLASS_STRUCT::ADAPT_CLASS_STRUCT() : - TempProtos(NIL_LIST) { - zero_all_bits(PermProtos, WordsInVectorOfSize(MAX_NUM_PROTOS)); - zero_all_bits(PermConfigs, WordsInVectorOfSize(MAX_NUM_CONFIGS)); -- -- for (int i = 0; i < MAX_NUM_CONFIGS; i++) { -- TempConfigFor(this, i) = nullptr; -- } - } - - ADAPT_CLASS_STRUCT::~ADAPT_CLASS_STRUCT() { -@@ -92,25 +88,24 @@ ADAPT_CLASS_STRUCT::~ADAPT_CLASS_STRUCT() { - - /// Constructor for adapted templates. - /// Add an empty class for each char in unicharset to the newly created templates. --ADAPT_TEMPLATES_STRUCT::ADAPT_TEMPLATES_STRUCT(UNICHARSET &unicharset) { -- Templates = new INT_TEMPLATES_STRUCT; -- NumPermClasses = 0; -- NumNonEmptyClasses = 0; -- -- /* Insert an empty class for each unichar id in unicharset */ -- for (unsigned i = 0; i < MAX_NUM_CLASSES; i++) { -- Class[i] = nullptr; -- if (i < unicharset.size()) { -- AddAdaptedClass(this, new ADAPT_CLASS_STRUCT, i); -- } -+ADAPT_TEMPLATES_STRUCT::ADAPT_TEMPLATES_STRUCT(UNICHARSET &unicharset) : -+ Templates(new INT_TEMPLATES_STRUCT), NumNonEmptyClasses(0), NumPermClasses(0) { -+ // Insert an empty class for each unichar id in unicharset. -+ // Class is value-initialized to nullptr in-class. -+ for (unsigned i = 0; i < unicharset.size(); i++) { -+ AddAdaptedClass(this, new ADAPT_CLASS_STRUCT, i); - } +@@ -107,10 +107,14 @@ ADAPT_TEMPLATES_STRUCT::ADAPT_TEMPLATES_STRUCT(UNICHARSET &unicharset) { } ADAPT_TEMPLATES_STRUCT::~ADAPT_TEMPLATES_STRUCT() { @@ -127,7 +97,7 @@ } // Returns FontinfoId of the given config of the given adapted class. -@@ -180,23 +175,32 @@ void Classify::PrintAdaptedTemplates(FILE *File, ADAPT_TEMPLATES_STRUCT *Templat +@@ -180,23 +184,32 @@ void Classify::PrintAdaptedTemplates(FILE *File, ADAPT_TEMPLATES_STRUCT *Templat * @note Globals: none */ ADAPT_CLASS_STRUCT *ReadAdaptedClass(TFile *fp) { @@ -165,7 +135,7 @@ Class->TempProtos = NIL_LIST; for (i = 0; i < NumTempProtos; i++) { auto TempProto = new TEMP_PROTO_STRUCT; -@@ -204,8 +208,20 @@ ADAPT_CLASS_STRUCT *ReadAdaptedClass(TFile *fp) { +@@ -204,8 +217,20 @@ ADAPT_CLASS_STRUCT *ReadAdaptedClass(TFile *fp) { Class->TempProtos = push_last(Class->TempProtos, TempProto); } @@ -187,7 +157,7 @@ for (i = 0; i < NumConfigs; i++) { if (test_bit(Class->PermConfigs, i)) { Class->Config[i].Perm = ReadPermConfig(fp); -@@ -231,18 +247,35 @@ ADAPT_CLASS_STRUCT *ReadAdaptedClass(TFile *fp) { +@@ -231,18 +256,35 @@ ADAPT_CLASS_STRUCT *ReadAdaptedClass(TFile *fp) { ADAPT_TEMPLATES_STRUCT *Classify::ReadAdaptedTemplates(TFile *fp) { auto Templates = new ADAPT_TEMPLATES_STRUCT; @@ -336,7 +306,15 @@ delete ProtoSets[i]; } } -@@ -613,8 +613,10 @@ INT_TEMPLATES_STRUCT::~INT_TEMPLATES_STRUCT() { +@@ -608,13 +610,18 @@ INT_TEMPLATES_STRUCT::INT_TEMPLATES_STRUCT() { + for (int i = 0; i < MAX_NUM_CLASSES; i++) { + ClassForClassId(this, i) = nullptr; + } ++ for (int i = 0; i < MAX_NUM_CLASS_PRUNERS; i++) { ++ ClassPruners[i] = nullptr; ++ } + } + INT_TEMPLATES_STRUCT::~INT_TEMPLATES_STRUCT() { - for (unsigned i = 0; i < NumClasses; i++) { + // The counts come from an untrusted file, so never trust them to bound
