GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service.



This issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3.

Project Subscriptions

Vendors Products
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 06 Oct 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 06 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service. This issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3.
Title Integer Truncation Leading to Heap Corruption in GNU Aspell
First Time appeared Gnu
Gnu aspell
Weaknesses CWE-190
CPEs cpe:2.3:a:gnu:aspell:*:*:*:*:*:*:*:*
Vendors & Products Gnu
Gnu aspell
References
Metrics cvssV4_0

{'score': 1.8, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: CERT-PL

Published:

Updated: 2026-10-06T12:49:39.265Z

Reserved: 2026-08-18T10:13:29.246Z

Link: CVE-2026-75820

cve-icon Vulnrichment

Updated: 2026-10-06T12:49:21.504Z

cve-icon NVD

Status : Received

Published: 2026-10-06T11:17:30.020

Modified: 2026-10-06T13:16:50.053

Link: CVE-2026-75820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-06T14:15:17Z

Weaknesses