Out-of-Bounds Read Vulnerability in GNU Aspell by GNU
CVE-2026-75819
What is CVE-2026-75819?
GNU Aspell is affected by an out-of-bounds read vulnerability occurring in the ReadOnlyDict::load() function within readonly_ws.cpp. This security flaw allows attackers to exploit the application by providing a malicious binary .rws dictionary file. The vulnerability arises when the application uses offset fields from the file header as byte indices into a heap buffer without adequate boundary validation. As a result, an attacker can manipulate a user into executing aspell with a crafted dictionary file through various options, potentially leading to heap memory disclosure or an application crash. The issue is addressed in commit 941953b25031bc9104e83f58e138a664b8dedc3f and is set to be resolved in version 0.60.8.3.
Affected Version(s)
Aspell 0 < 0.60.8.3
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved