AZL-105966

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105966.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-105966
Upstream
Published
2026-10-06T11:17:30Z
Modified
2026-10-07T14:16:55Z
Summary
CVE-2026-75820 affecting package aspell 0.60.8.1-1
Details

GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service.

This issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3.

References

Affected packages

Azure Linux:3 / aspell

Package

Name
aspell
Purl
pkg:rpm/azure-linux/aspell

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.60.8.1-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105966.json"