Skip to content
Critical Gzip Vulnerabilities in Ubuntu Expose Systems to Local Attacks

Critical Gzip Vulnerabilities in Ubuntu Expose Systems to Local Attacks

First seen 6 Jul 2026, 23:49 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •July 7, 2026 at 21:39 UTC

Two critical vulnerabilities were discovered in Gzip's gzexe utility and file handling. CVE-2026-41991 allows local attackers to overwrite arbitrary files via a predictable temporary file path. CVE-2026-41992 can lead to denial of service or exposure of sensitive information due to improper handling of compressed files. These vulnerabilities affect multiple Ubuntu versions, including 22.04, 24.04, and 26.04 LTS. Users are advised to update their systems to mitigate these risks. The issues were published on June 29, 2026, and are now addressed in the latest updates. A standard system update will apply the necessary patches.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 95d ago How this analysis works

Timeline

2026-06-29
CVE-2026-41991 published
Local attackers can exploit Gzip's gzexe utility due to insecure temporary file handling.
Ubuntu
2026-06-29
CVE-2026-41992 published
Gzip's improper handling of compressed files can lead to denial of service or data exposure.
Ubuntu
2026-07-06
Ubuntu security notice USN-8512-1 released
Ubuntu issued a notice addressing critical vulnerabilities in Gzip, urging users to update.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track Ubuntu and CVE-2026-41991 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed