https://seclists.org/oss-sec/2026/q4/124: 3 Vulnerabilities in GNU Aspell befo0.60.8.3
Published Oct 9, 2026
·Updated
Affected Software
1 affected component
GNU aspell<0.60.8.3
Users who process attacker-controlled compressed files with prezip-bin are exposed. Exploitation requires convincing a user to process a crafted compressed file.
The crafted file can cause out-of-bounds heap reads and writes, resulting in memory corruption. The reported consequence is a crash of the prezip-bin process.
The fix is in commit 15b188437f9e0192d4ac4472ad66a4e2f62a782f and is stated to be released in GNU Aspell version 0.60.8.3.
A malicious binary .rws dictionary can be supplied through the --master option, the --dict-dir option, or configuration options. The issue occurs while aspell loads the dictionary file.