CVE-2026-75820
Integer Truncation Leading to Heap Corruption in GNU Aspell
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service. This issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3.
| CWE | CWE-190 |
| Vendor | gnu |
| Product | aspell |
| Published | Oct 6, 2026 |
Stay Ahead of the Next One
Get instant alerts for gnu aspell
Be the first to know when new unknown vulnerabilities affecting gnu aspell are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
GNU / Aspell
0 < 0.60.8.3
References
Credits
Michał Majchrowicz (AFINE Team) Marcin Wyczechowski (AFINE Team)