CVE-2026-75820EPSS p2.0%
CVE-2026-75820CVE-2026-75820
Description
GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service.
This issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3.
Scoring
| EPSS | 0.13% probability of exploitation · percentile 2.0% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-06 |