GNU Aspell patches three memory-corruption flaws
Free public brief. The indicators, the detections with Splunk and KQL already written, and a Slack alert the next time this touches a vendor you run are in the app — free account, no card.
Three CVEs in GNU Aspell allow heap corruption via crafted compressed files, dictionary files, or wordlists; fixed in 0.60.8.3.
CERT Polska coordinated disclosure of three vulnerabilities in GNU Aspell, a widely used open-source spell-checking library, reported by AFINE Team researchers. CVE-2026-75818 is a heap-based buffer overflow in the prezip-bin decompressor (prog/prezip.c) caused by missing buffer-space checks, allowing out-of-bounds read/write via a crafted compressed file and leading to process crash. CVE-2026-75819 is an out-of-bounds read in ReadOnlyDict::load() (readonly_ws.cpp), where unvalidated offset fields from a .rws dictionary file header are used as heap buffer indices, enabling memory disclosure or crash when loading a malicious dictionary via --master, --dict-dir, or configuration options. CVE-2026-75820 is an integer truncation bug in WritableDict::add() (writable.cpp) where word lengths stored as a single byte truncate for lengths that are multiples of 256, causing heap corruption when loading a crafted personal wordlist.
All three require user interaction — convincing a victim to process a malicious compressed file, dictionary, or wordlist with Aspell — and result primarily in denial of service (crash), with CVE-2026-75819 additionally risking heap memory disclosure. No in-the-wild exploitation has been reported; this is a coordinated disclosure with fixes already merged. Defenders should upgrade to GNU Aspell version 0.60.8.3 once released, or apply the referenced upstream commits, and avoid processing untrusted compressed files, dictionary files, or wordlists with affected Aspell components in the interim.
Mentioned in this report
Detection guidance
GNU Aspell Loading Dictionary or Wordlist From User-Writable Path
aspell invoked with --master, --dict-dir or --personal pointing at temp or download directories, the delivery path for crafted .rws dictionaries or personal wordlists (CVE-2026-75819/75820). Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: GNU Aspell Loading Dictionary or Wordlist From User-Writable Path
id: 073f092a-bf04-59cf-9413-e70246f6fcd2
status: experimental
description: Detects aspell run with dictionary or wordlist options (--master, --dict-dir,
--personal) pointing at user-writable or download locations. Crafted .rws dictionaries
or personal wordlists delivered this way can trigger heap memory corruption in aspell
(CVE-2026-75819, CVE-2026-75820). Hunting rule; no in-the-wild exploitation is reported.
Matches the option-plus-path pattern, not any specific filename.
tags:
- attack.execution
- attack.t1203
logsource:
category: process_creation
product: linux
detection:
selection_img:
Image|endswith: /aspell
selection_opt:
CommandLine|contains:
- --master
- --dict-dir
- --personal
selection_path:
CommandLine|contains:
- /tmp/
- /var/tmp/
- /dev/shm/
- /Downloads/
condition: selection_img and selection_opt and selection_path
falsepositives:
- Developers or linguists testing custom dictionaries extracted to /tmp
- Packaging or CI jobs that build and validate Aspell dictionaries in temporary build
directories
level: low
author: Vorant
references:
- https://cert.pl/en/posts/2026/10/CVE-2026-75818
Aspell prezip-bin Processing File From User-Writable Path
prezip-bin executed against files in temp or download directories, the route for crafted compressed input that triggers the heap overflow (CVE-2026-75818). Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.
title: Aspell prezip-bin Processing File From User-Writable Path
id: 52828ef7-00cc-58bc-90b3-dd02c0dbe96d
status: experimental
description: Detects the Aspell prezip-bin decompressor run with arguments referencing
temp or download directories. A crafted compressed file processed this way can cause
a heap-based buffer overflow (CVE-2026-75818), usually a crash. Hunting rule; no
in-the-wild exploitation is reported.
tags:
- attack.execution
- attack.t1203
logsource:
category: process_creation
product: linux
detection:
selection:
Image|endswith: /prezip-bin
CommandLine|contains:
- /tmp/
- /var/tmp/
- /dev/shm/
- /Downloads/
condition: selection
falsepositives:
- Maintainers building or testing Aspell word lists with the compression tools in
a temporary directory
- Distribution packaging scripts that run prezip-bin in a build root under /tmp
level: low
author: Vorant
references:
- https://cert.pl/en/posts/2026/10/CVE-2026-75818
1 more detection for this report is in the app — the rules that match its indicators, plus every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. Three days of it free, no card.
Behavioural rules are generated from public reporting — validate in your environment before deploying.
Source reporting: https://cert.pl/en/posts/2026/10/CVE-2026-75818
What this brief leaves out
This page is the free tier: the write-up, the severity, the names. In the app the same report carries its extracted indicators, its detections with the Splunk SPL and Microsoft KQL already written, the actors and CVEs it names as live profiles, and the vendor research on the same campaign — the primary source the news paraphrased, cited and read directly.
It sits in a corpus of 10,812 reports from 152 sources, 462 of them written in the last seven days, and it grows through the day.
A new account starts with three days of all of it, no card, then keeps the government and CERT reporting free. Name the vendors you run and Slack hears about the reports that touch them — about forty a week that are yours, not the four hundred that are not.
Create a free account What it costs