Integer Truncation Vulnerability in GNU Aspell's WritableDict Function
CVE-2026-75820

1.8LOW

Key Information:

Vendor

Gnu

Status
Vendor
CVE Published:
6 October 2026

What is CVE-2026-75820?

GNU Aspell contains a vulnerability in the WritableDict::add() function due to improper handling of word lengths stored as a single byte when loading personal wordlists. This can lead to truncation for words that are multiples of 256 characters, resulting in heap corruption. An attacker might exploit this flaw by enticing a user to utilize a specially crafted personal wordlist, potentially leading to a denial of service.

Affected Version(s)

Aspell 0 < 0.60.8.3

References

CVSS V4

Score:
1.8
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michał Majchrowicz (AFINE Team)
Marcin Wyczechowski (AFINE Team)
.