CVE-2026-75818
Heap Buffer Overflow in GNU Aspell's prezip utility
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
GNU Aspell prezip-bin contains a heap-based buffer overflow vulnerability in the decompressor in prog/prezip.c. The decompressor does not properly check buffer space, so a crafted compressed file can cause out-of-bounds read and write operations on the heap. An attacker who convinces a user to process a malicious compressed file with prezip-bin can trigger memory corruption, leading to a processs crash. This issue was fixed in commit 15b188437f9e0192d4ac4472ad66a4e2f62a782f which will be released in version 0.60.8.3.
| CWE | CWE-122 |
| Vendor | gnu |
| Product | aspell |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for gnu aspell
Be the first to know when new unknown vulnerabilities affecting gnu aspell are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
GNU / Aspell
0 < 0.60.8.3
References
Credits
Michał Majchrowicz (AFINE Team) Marcin Wyczechowski (AFINE Team)