Full Report
CERT Polska has received a report about 3 vulnerabilities (from CVE-2026-75818 to CVE-2026-75820) found in GNU Aspell software.
Analysis Summary
# Vulnerability: Multiple Flaws in GNU Aspell (Buffer Overflow, OOB Read, Integer Truncation)
## CVE Details
- **CVE ID:** CVE-2026-75818, CVE-2026-75819, CVE-2026-75820
- **CVSS Score:** Not explicitly provided in the source (Typically High for memory corruption/overflows)
- **CWE:**
- CWE-122: Heap-based Buffer Overflow (CVE-2026-75818)
- CWE-125: Out-of-bounds Read (CVE-2026-75819)
- CWE-190: Integer Overflow or Wraparound / Truncation (CVE-2026-75820)
## Affected Systems
- **Products:** GNU Aspell
- **Versions:** All versions before 0.60.8.3
- **Configurations:** Systems utilizing `prezip-bin` for decompression or loading external dictionary files (`.rws`) and personal wordlists.
## Vulnerability Description
GNU Aspell is affected by three distinct memory safety vulnerabilities:
1. **CVE-2026-75818:** A heap-based buffer overflow in `prog/prezip.c` within the `prezip-bin` utility. The decompressor fails to validate buffer space, allowing crafted compressed files to trigger out-of-bounds heap operations.
2. **CVE-2026-75819:** An out-of-bounds read in `ReadOnlyDict::load()` within `readonly_ws.cpp`. The software fails to validate offset fields in binary `.rws` dictionary headers, using them as direct indices into a heap buffer.
3. **CVE-2026-75820:** An integer truncation flaw in `WritableDict::add()`. Word lengths in personal wordlists are stored as a single byte. Words with lengths that are multiples of 256 cause truncation, leading to heap corruption.
## Exploitation
- **Status:** PoC availability not explicitly stated, but technical details are documented. No reported exploitation in the wild.
- **Complexity:** Medium (Requires user interaction to process malicious files).
- **Attack Vector:** Local/Adjacent (Attacker must provide a malicious file—compressed file, dictionary, or wordlist—to the user).
## Impact
- **Confidentiality:** Medium (CVE-2026-75819 allows heap memory disclosure).
- **Integrity:** High (Memory corruption and heap overflows can lead to process hijacking).
- **Availability:** High (All three vulnerabilities can lead to application crashes and Denial of Service).
## Remediation
### Patches
Users should update to **GNU Aspell version 0.60.8.3** or later. Specific fixes are available via the following Git commits:
- **CVE-2026-75818:** Commit `15b188437f9e0192d4ac4472ad66a4e2f62a782f`
- **CVE-2026-75819:** Commit `941953b25031bc9104e83f58e138a664b8dedc3f`
- **CVE-2026-75820:** Commit `782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d`
### Workarounds
- Avoid using `prezip-bin` to decompress files from untrusted sources.
- Do not use the `--master` or `--dict-dir` flags with dictionary files provided by unknown third parties.
- Inspect personal wordlists for unusually long strings before processing.
## Detection
- **Indicators of Compromise:** Unexpected application crashes (SIGSEGV) when processing `.rws` or compressed prezip files.
- **Detection Methods:** Security teams can use static analysis to check for vulnerable versions of `libaspell` or the `aspell` binary. Fuzzing dictionary files or wordlists may also identify these memory corruption triggers.
## References
- CERT Polska Advisory: hxxps[://]cert[.]pl/en/posts/2026/10/vulnerabilities-in-gnu-aspell/
- CVE-2026-75818: hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-75818
- CVE-2026-75819: hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-75819
- CVE-2026-75820: hxxps[://]www[.]cve[.]org/CVERecord?id=CVE-2026-75820
- CWE-122: hxxps[://]cwe[.]mitre[.]org/data/definitions/122[.]html