RHSA-2026:61623: Moderate: gzip security update
Moderate: gzip security update
Other sources
The gzip packages contain the gzip (GNU zip) data compression utility. gzip is used to compress regular files. It replaces them with files containing the .gz extension, while retaining ownership modes, access, and modification times.Security Fix(es): gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility (CVE-2026-41991) gzip: gzip: Information disclosure via global buffer overflow in LZH decompression (CVE-2026-41992) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gzipto a version that resolves this vulnerability.Fixed in 1.12-2.el9_8 - Upgrade
Upgrade
redhat/gzip-debuginfoto a version that resolves this vulnerability.Fixed in 1.12-2.el9_8 - Upgrade
Upgrade
redhat/gzip-debugsourceto a version that resolves this vulnerability.Fixed in 1.12-2.el9_8 - Upgrade
Upgrade
redhat/gzipto a version that resolves this vulnerability.Fixed in 1.12-2.el9_8.aa - Upgrade
Upgrade
redhat/gzip-debuginfoto a version that resolves this vulnerability.Fixed in 1.12-2.el9_8.aa - Upgrade
Upgrade
redhat/gzip-debugsourceto a version that resolves this vulnerability.Fixed in 1.12-2.el9_8.aa
Event History
Frequently Asked Questions
Which systems should be evaluated for this update?
Evaluate Red Hat Enterprise Linux deployments using gzip on IBM z Systems, Power little endian, x86_64, and ARM 64. This includes the listed Extended Life Cycle and 4-years-of-updates variants.
How urgent is remediation?
The advisory is rated Moderate with a severity value of 4 and a listed risk of 19. Prioritize it according to your organization's patching policy for medium-severity security updates.