Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-75820— Integer Truncation Leading to Heap Corruption in GNU Aspell

Quick assessment

Affected
GNU Aspell
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

GNU Aspell 中存在一个整数截断漏洞,位于 中的 函数内。当加载个人词表时,单词长度被存储为单个字节,导致长度为 256 倍数的单词发生截断。这引发了堆损坏。攻击者可通过诱使用户使用包含此类单词的恶意构造的个人词表运行 aspell,从而利用该漏洞导致拒绝服务(DoS)。 该问题已在提交 中修复,并将在版本 中发布。

CVSS 1.8 · Low

Possible ATT&CK Techniques 1 AI

T1203 · Exploitation for Client Execution
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75820

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Integer Truncation Leading to Heap Corruption in GNU Aspell
Source: CVE Program / CVE List V5
Vulnerability Description
GNU Aspell contains an integer truncation vulnerability in the WritableDict::add() function in modules/speller/default/writable.cpp. When loading a personal wordlist, the word length is stored as a single byte, causing truncation for words whose length is a multiple of 256. This leads to heap corruption. An attacker can exploit this by convincing a user to run aspell with a crafted personal wordlist containing such a word, resulting in denial of service. This issue was fixed in commit 782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d which will be released in version 0.60.8.3.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:L/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
整数溢出或超界折返
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
GNU Aspell 0 ~ 0.60.8.3 -

II. Public POCs for CVE-2026-75820

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75820

请登录查看更多情报信息。

Other References for CVE-2026-75820 (2)

Same Patch Batch · GNU · 2026-10-06 · 3 CVEs total

CVE-2026-75819 1.8 LOW Out-of-bounds Read in GNU Aspell
CVE-2026-75818 1.8 LOW Heap Buffer Overflow in GNU Aspell's prezip utility

IV. Related Vulnerabilities

V. Comments for CVE-2026-75820

No comments yet


Leave a comment