Linuxsecurity Critical Gzip Vulnerabilities in Ubuntu Expose Systems to Local Attacks
Article Content
- •CVE-2026-41991 allows local attackers to exploit predictable file paths in Gzip.
- •CVE-2026-41992 can cause denial of service or expose sensitive data.
- •Affected Ubuntu versions include 22.04, 24.04, and 26.04 LTS; users should update immediately.
Two critical vulnerabilities were discovered in Gzip's gzexe utility and file handling. CVE-2026-41991 allows local attackers to overwrite arbitrary files via a predictable temporary file path. CVE-2026-41992 can lead to denial of service or exposure of sensitive information due to improper handling of compressed files. These vulnerabilities affect multiple Ubuntu versions, including 22.04, 24.04, and 26.04 LTS. Users are advised to update their systems to mitigate these risks. The issues were published on June 29, 2026, and are now addressed in the latest updates. A standard system update will apply the necessary patches.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track Ubuntu and CVE-2026-41991 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…