Gzip Vulnerabilities Expose Systems to Local Attacks

Gzip Vulnerabilities Expose Systems to Local Attacks

First seen 8 Sep 2026, 15:13 UTC UbuntuLinuxsecurity 45.9

Article Content

Browse articles
ThreatCluster

Recent vulnerabilities in Gzip, discovered by Michał Majchrowicz, Marcin Wyczechowski, and Elias Hasas, affect systems using the gzexe utility. The vulnerabilities include CVE-2026-41991, where insecure temporary file creation could allow local attackers to overwrite arbitrary files, and CVE-2026-41992, which could lead to information disclosure or denial of service due to improper handling of certain compressed files. These issues impact Gzip versions in Ubuntu systems, particularly Ubuntu 16.04 LTS. Users are advised to update their systems to mitigate these risks. The vulnerabilities were published on June 29, 2026, and a standard system update is recommended for remediation.

Key Points: • Two critical vulnerabilities identified in Gzip: CVE-2026-41991 and CVE-2026-41992. • Local attackers can exploit these vulnerabilities to overwrite files or cause denial of service. • Affected systems include Ubuntu 16.04 LTS; users should apply updates promptly.

Ask AI about this cluster

Timeline

2026-06-29
CVE-2026-41991 and CVE-2026-41992 published
Two vulnerabilities in Gzip were disclosed, allowing local file overwriting and denial of service.
Ubuntu
2026-09-07
Ubuntu Security Notice USN-8733-1 released
Ubuntu announced security updates for Gzip to address the vulnerabilities.
Ubuntu
2026-09-08
Linuxsecurity reports on Gzip vulnerabilities
Linuxsecurity provided details on the vulnerabilities and urged users to update their systems.
Linuxsecurity