CVE-2026-75820
Received Received - Intake

Heap Corruption in GNU Aspell via Wordlist Truncation

Vulnerability report for CVE-2026-75820, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-06

Last updated on: 2026-10-06

Assigner: CERT.PL

Description

GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service. This issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387dΒ which will beΒ released in versionΒ 0.60.8.3.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-06
Last Modified
2026-10-06
Generated
2026-10-06
AI Q&A
2026-10-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
GNU Aspell 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-190 The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

GNU Aspell has an integer truncation vulnerability in the WritableDict::add() function. When loading a personal wordlist, word length is stored as a single byte, which truncates words whose length is a multiple of 256. This causes heap corruption. An attacker can exploit this by tricking a user into running aspell with a specially crafted wordlist containing such a word, leading to denial of service.

Detection Guidance

To detect this vulnerability, check the version of GNU Aspell installed on your system. If it is below 0.60.8.3, the system is vulnerable. Run: aspell --version. Additionally, monitor for crashes or heap corruption when processing personal wordlists.

Impact Analysis

This vulnerability can cause denial of service when a user processes a crafted wordlist. It may crash the application or system, disrupting normal operations. The impact is limited to local users since exploitation requires user interaction to load the malicious wordlist.

Mitigation Strategies

Update GNU Aspell to version 0.60.8.3 or later. If updating is not immediately possible, avoid using personal wordlists with aspell until the update is applied. Remove any untrusted personal wordlists that may contain crafted words.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75820. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart