RHSA-2026:61625: Moderate: gzip security update
Moderate: gzip security update
Other sources
The gzip packages contain the gzip (GNU zip) data compression utility. gzip is used to compress regular files. It replaces them with files containing the .gz extension, while retaining ownership modes, access, and modification times.Security Fix(es): gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility (CVE-2026-41991) gzip: gzip: Information disclosure via global buffer overflow in LZH decompression (CVE-2026-41992) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/gzipto a version that resolves this vulnerability.Fixed in 1.13-4.el10_2 - Upgrade
Upgrade
redhat/gzip-debuginfoto a version that resolves this vulnerability.Fixed in 1.13-4.el10_2 - Upgrade
Upgrade
redhat/gzip-debugsourceto a version that resolves this vulnerability.Fixed in 1.13-4.el10_2 - Upgrade
Upgrade
redhat/gzipto a version that resolves this vulnerability.Fixed in 1.13-4.el10_2.aa - Upgrade
Upgrade
redhat/gzip-debuginfoto a version that resolves this vulnerability.Fixed in 1.13-4.el10_2.aa - Upgrade
Upgrade
redhat/gzip-debugsourceto a version that resolves this vulnerability.Fixed in 1.13-4.el10_2.aa
Event History
Frequently Asked Questions
Which deployments are covered by this update?
The update applies to Red Hat Enterprise Linux on x86_64, ARM 64, IBM z Systems, and little-endian Power. Listed support streams include standard support, Extended Update Support, and four-year update or support offerings, depending on architecture.
What priority does the advisory assign to this update?
The advisory rates the issue as Moderate severity with a severity value of 4 and lists a risk value of 19.