{"id":"AZL-105966","summary":"CVE-2026-75820 affecting package aspell 0.60.8.1-1","details":"GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service.\n\n\n\nThis issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3.","modified":"2026-10-07T14:16:55.506477730Z","published":"2026-10-06T11:17:30Z","upstream":["CVE-2026-75820"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75820"}],"affected":[{"package":{"name":"aspell","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/aspell"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"0.60.8.1-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-105966.json"}}],"schema_version":"1.9.0"}