# GNU Aspell patches three memory-corruption flaws

Published: 2026-10-06 · Severity: routine
Canonical: https://vorant.io/reports/c03b7050-aa49-54df-80eb-c19d3f1a86e6/gnu-aspell-patches-three-memory-corruption-flaws

> Three CVEs in GNU Aspell allow heap corruption via crafted compressed files, dictionary files, or wordlists; fixed in 0.60.8.3.

CERT Polska coordinated disclosure of three vulnerabilities in GNU Aspell, a widely used open-source spell-checking library, reported by AFINE Team researchers. CVE-2026-75818 is a heap-based buffer overflow in the prezip-bin decompressor (prog/prezip.c) caused by missing buffer-space checks, allowing out-of-bounds read/write via a crafted compressed file and leading to process crash. CVE-2026-75819 is an out-of-bounds read in ReadOnlyDict::load() (readonly_ws.cpp), where unvalidated offset fields from a .rws dictionary file header are used as heap buffer indices, enabling memory disclosure or crash when loading a malicious dictionary via --master, --dict-dir, or configuration options. CVE-2026-75820 is an integer truncation bug in WritableDict::add() (writable.cpp) where word lengths stored as a single byte truncate for lengths that are multiples of 256, causing heap corruption when loading a crafted personal wordlist.

All three require user interaction — convincing a victim to process a malicious compressed file, dictionary, or wordlist with Aspell — and result primarily in denial of service (crash), with CVE-2026-75819 additionally risking heap memory disclosure. No in-the-wild exploitation has been reported; this is a coordinated disclosure with fixes already merged. Defenders should upgrade to GNU Aspell version 0.60.8.3 once released, or apply the referenced upstream commits, and avoid processing untrusted compressed files, dictionary files, or wordlists with affected Aspell components in the interim.

## Mentioned in this report

- Vulnerabilities: CVE-2026-75818, CVE-2026-75819, CVE-2026-75820

## Detection guidance (public sample)

### GNU Aspell Loading Dictionary or Wordlist From User-Writable Path

ATT&CK: T1203

aspell invoked with --master, --dict-dir or --personal pointing at temp or download directories, the delivery path for crafted .rws dictionaries or personal wordlists (CVE-2026-75819/75820). Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: GNU Aspell Loading Dictionary or Wordlist From User-Writable Path
id: 073f092a-bf04-59cf-9413-e70246f6fcd2
status: experimental
description: Detects aspell run with dictionary or wordlist options (--master, --dict-dir,
  --personal) pointing at user-writable or download locations. Crafted .rws dictionaries
  or personal wordlists delivered this way can trigger heap memory corruption in aspell
  (CVE-2026-75819, CVE-2026-75820). Hunting rule; no in-the-wild exploitation is reported.
  Matches the option-plus-path pattern, not any specific filename.
tags:
- attack.execution
- attack.t1203
logsource:
  category: process_creation
  product: linux
detection:
  selection_img:
    Image|endswith: /aspell
  selection_opt:
    CommandLine|contains:
    - --master
    - --dict-dir
    - --personal
  selection_path:
    CommandLine|contains:
    - /tmp/
    - /var/tmp/
    - /dev/shm/
    - /Downloads/
  condition: selection_img and selection_opt and selection_path
falsepositives:
- Developers or linguists testing custom dictionaries extracted to /tmp
- Packaging or CI jobs that build and validate Aspell dictionaries in temporary build
  directories
level: low
author: Vorant
references:
- https://cert.pl/en/posts/2026/10/CVE-2026-75818
```

### Aspell prezip-bin Processing File From User-Writable Path

ATT&CK: T1203

prezip-bin executed against files in temp or download directories, the route for crafted compressed input that triggers the heap overflow (CVE-2026-75818). Auto-generated starting point — validate and tune in your environment before deploying. IOC matches can false-positive on shared infrastructure and decay as adversary infrastructure rotates.

```yaml
title: Aspell prezip-bin Processing File From User-Writable Path
id: 52828ef7-00cc-58bc-90b3-dd02c0dbe96d
status: experimental
description: Detects the Aspell prezip-bin decompressor run with arguments referencing
  temp or download directories. A crafted compressed file processed this way can cause
  a heap-based buffer overflow (CVE-2026-75818), usually a crash. Hunting rule; no
  in-the-wild exploitation is reported.
tags:
- attack.execution
- attack.t1203
logsource:
  category: process_creation
  product: linux
detection:
  selection:
    Image|endswith: /prezip-bin
    CommandLine|contains:
    - /tmp/
    - /var/tmp/
    - /dev/shm/
    - /Downloads/
  condition: selection
falsepositives:
- Maintainers building or testing Aspell word lists with the compression tools in
  a temporary directory
- Distribution packaging scripts that run prezip-bin in a build root under /tmp
level: low
author: Vorant
references:
- https://cert.pl/en/posts/2026/10/CVE-2026-75818
```

Behavioural rules are generated from public reporting — validate in your environment before deploying.

1 more detection for this report is in the app: the rules that match its indicators, every rule converted to Splunk SPL and Elastic, Microsoft Defender XDR KQL wherever Defender records the activity, and the YARA and Suricata. A new account gets three days of them free.

Source reporting: https://cert.pl/en/posts/2026/10/CVE-2026-75818

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/c03b7050-aa49-54df-80eb-c19d3f1a86e6/gnu-aspell-patches-three-memory-corruption-flaws.
In the app the same report carries its extracted indicators, its detections with Splunk SPL and Microsoft KQL already written, live profiles of the actors and CVEs it names, and the vendor research on the same campaign. Slack alerts fire on the vendors, sectors and countries a reader follows. A new account starts with three days of all of it, no card: https://vorant.io/signup
