{"id":"CVE-2026-75820","summary":"Integer Truncation Leading to Heap Corruption in GNU Aspell","details":"GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service.\n\n\n\nThis issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3.","modified":"2026-10-07T02:47:33.820270824Z","published":"2026-10-06T10:57:59.621Z","database_specific":{"cna_assigner":"CERT-PL","cwe_ids":["CWE-190"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75820.json","unresolved_ranges":[{"extracted_events":[{"fixed":"0.60.8.3"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"http://aspell.net/"},{"type":"ADVISORY","url":"https://cert.pl/en/posts/2026/10/CVE-2026-75818"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75820.json"},{"type":"PACKAGE","url":"https://github.com/GNUAspell/aspell"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75820"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/gnuaspell/aspell","events":[{"introduced":"0"},{"last_affected":"3de79d40aee4e9ccdc0d83856637949801a3d33b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"0.60.8.2"}],"source":"CPE_FIELD"}}],"versions":["rel-0.60.8.2","rel-0.60.6.1","rel-0.60.7-20110707"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75820.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N"}]}