{"id":"CVE-2026-75820","title":"GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp","summary":"GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for wor…","severity":"low","cvss":1.8,"cvssVector":"CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N","cwe":["CWE-190"],"vendor":"GNU","product":"Aspell","affected":["Aspell < 0.60.8.3"],"published":"2026-10-06","updated":"2026-10-06","sourceUpdated":"2026-10-06T11:17:30.020","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75820","references":[{"url":"http://aspell.net/","label":"cvd@cert.pl"},{"url":"https://cert.pl/en/posts/2026/10/CVE-2026-75818","label":"cvd@cert.pl"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-10-06T11:57:26.914Z","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-06T12:49:13.392681Z"},"slug":"CVE-2026-75820","body":"## Overview\n\nGNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service.\n\n\n\nThis issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":10,"depthScoreParts":{"impact":9.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}