Hi, The following vulnerability was published for gzip. CVE-2026-41991[0]: | GNU gzip contains a vulnerability in the gzexe utility related to | insecure temporary file handling. When the mktemp utility is not | available in the user’s PATH, gzexe falls back to constructing a | temporary file path based solely on the process ID (PID). This | predictable filename is created without exclusive access or | existence checks. A local attacker can pre‑create the predicted | temporary file path as a symbolic link pointing to an arbitrary file | writable by the victim. When gzexe runs, it follows the symlink and | overwrites the target file, resulting in a time‑of‑check to | time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite. | This issue has been fixed in the commit | 4e6f8b24ab823146ab8776f0b7fe486ab34d4269 If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-41991 https://www.cve.org/CVERecord?id=CVE-2026-41991 [1] https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
gzip, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1141442@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Milan Kupcevic <milan@debian.org> (supplier of updated gzip package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 16 Aug 2026 21:14:53 -0400
Source: gzip
Architecture: source
Version: 1.14-1
Distribution: sid
Urgency: medium
Maintainer: Milan Kupcevic <milan@debian.org>
Changed-By: Milan Kupcevic <milan@debian.org>
Closes: 513754 1137242 1141442 1141443
Changes:
gzip (1.14-1) sid; urgency=medium
.
[ Milan Kupcevic ]
* new upstream release
- gzexe, zdiff, zgrep: Switch scripts from using `type` to
`command -v` to support non-XSI, closes: #513754
* cherry-pick upstream uninitialized read fix
* d/p/CVE-2026-41991-a.patch, d/p/CVE-2026-41991-b.patch: use -C if
lacking mktemp, closes: #1141442, CVE-2026-41991
* d/p/CVE-2026-41992.patch: gzip: don’t mishandle .lzh after .Z,
closes: #1141443, CVE-2026-41992
* d/control: comply to standards version 4.7.4
.
[ Grayson Wolf ]
* add more complex autopkgtest scripts, closes: #1137242
.
gzip (1.14-1~exp2) experimental; urgency=medium
.
* d/rules: configure set /bin/sh and grep; autoreconf cleanup
.
gzip (1.14-1~exp1) experimental; urgency=medium
.
* new upstream release
.
gzip (1.13.56~e549-1~exp1) experimental; urgency=medium
.
* new upstream release
* d/patches: quilt refresh
* d/copyright: update
* d/rules: use debhelper leverage
* d/control: comply to standards version 4.7.2
* d/patches/disable-Werror.patch: drop
Checksums-Sha1:
069e4182547a4721f4c6493ed681fea29c98ba99 1908 gzip_1.14-1.dsc
2c4407eec3693261616b7e93524d82a187222104 22540 gzip_1.14-1.debian.tar.xz
c316bb9a31481b986622d589da16a910b8e4836c 5983 gzip_1.14-1_amd64.buildinfo
Checksums-Sha256:
8c02e8f12a2f9f45db2fe4de1a65900f47311c2d1e49f839b00172d9c420ef03 1908 gzip_1.14-1.dsc
f3e0edcb4092dbcf62ff0b7ac068fddb4ba7b644c55edf005b25415f9d9ce628 22540 gzip_1.14-1.debian.tar.xz
7343425201cca344aa5396dac2b3f37bb1aa0f8e0e59fc2547703b7f483e34ca 5983 gzip_1.14-1_amd64.buildinfo
Files:
516cc7357bbd0bcfd3134417dd261c7b 1908 utils required gzip_1.14-1.dsc
66c7b0b60b823b3b6cde7abb662e5e02 22540 utils required gzip_1.14-1.debian.tar.xz
fe885667f28ef226379927544a740d24 5983 utils required gzip_1.14-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQHFBAEBCgAvFiEEVkf/m69krCYf+z+G6e1ngbRVCQ4FAmqCbvoRHG1pbGFuQGRl
Ymlhbi5vcmcACgkQ6e1ngbRVCQ56DgwAyGcHYaF1vUAC9oZm4jo4QIOgpfhk/CXS
Ie32KgRKuuHKQy/pRvEvi6V0cOvUO6rqm5qozz11zJsrotrTzJoPcpNDdYQgCaik
tts5rCqiCOQ16RbjLPj/8ATaWzMQwciLpKgv+PbaNVXeph6eSMfuK8MporIYTSpb
FqLn6WElBFU5XjwLfM27qjO/UBeLfP3FmKEH6R7KxxO6eOi+35qcu0MKMYs+3bSE
zDDDwtXuSoviQpKM+P0XgaspTYM4nt1uynm41LHQu12UXi40bcafDBvXnFrRLkpT
pDkpvd+7SZxhIFxjyqw5dK9qsm2XjnTDyyqY7WrDZRbmpmgoQysKmVU5d+P/CEFJ
EaonVh/dsYmU42YWQ5al9XcQodlQes1/vGYe1F8X99y7IovXlPwI2dfxwVXA6m84
4uh+pQKituqIIsJ6wdhsEY/BD9B95oED2TkV+J48wTXVI+69uxKM0uN3+pGCiXjK
F78M4k+S2YyULOiu/pE3EB/ZC04LHpCo
=aewa
-----END PGP SIGNATURE-----
We believe that the bug you reported is fixed in the latest version of
gzip, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1141442@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Milan Kupcevic <milan@debian.org> (supplier of updated gzip package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Mon, 24 Aug 2026 17:59:51 -0400
Source: gzip
Architecture: source
Version: 1.13-1+deb13u1
Distribution: trixie
Urgency: medium
Maintainer: Milan Kupcevic <milan@debian.org>
Changed-By: Milan Kupcevic <milan@debian.org>
Closes: 1141442 1141443
Changes:
gzip (1.13-1+deb13u1) trixie; urgency=medium
.
* d/p/CVE-2026-41991-a.patch, d/p/CVE-2026-41991-b.patch: use -C if
lacking mktemp, closes: #1141442, CVE-2026-41991
* d/p/CVE-2026-41992.patch: gzip: don’t mishandle .lzh after .Z,
closes: #1141443, CVE-2026-41992
Checksums-Sha1:
da29a1d6cbffd22cf19ba0acb51355aedae2c985 1708 gzip_1.13-1+deb13u1.dsc
8a722d74425395decd1588fb5b79a2ca97d5e549 21364 gzip_1.13-1+deb13u1.debian.tar.xz
7ff57df80023a2199a38313960f5ca7c34a50315 6325 gzip_1.13-1+deb13u1_amd64.buildinfo
Checksums-Sha256:
0c25763da4f7242fbe7e9185b69bcb3f986011b04446b66a84c52bbdf731d308 1708 gzip_1.13-1+deb13u1.dsc
ffc69d13290009f42dbb4d10a34839350eff3fdaf4be1fda03d10b238ba2f77d 21364 gzip_1.13-1+deb13u1.debian.tar.xz
f7e42973c1acb448431353123c4fbb75ead7e2c77072f701a08423d93fe0fc3b 6325 gzip_1.13-1+deb13u1_amd64.buildinfo
Files:
5976c64ae61b3af3fe844d22cf699723 1708 utils required gzip_1.13-1+deb13u1.dsc
d2c8e569ae5148078ab4261dc10efcb9 21364 utils required gzip_1.13-1+deb13u1.debian.tar.xz
024002db31fb65962b264fa3dedb02ad 6325 utils required gzip_1.13-1+deb13u1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQHFBAEBCgAvFiEEVkf/m69krCYf+z+G6e1ngbRVCQ4FAmqcEE8RHG1pbGFuQGRl
Ymlhbi5vcmcACgkQ6e1ngbRVCQ6l2AwA4SEEGQFmN3wTaDXe/S30DTx/0N++L5ma
fAEmoq0WqVX+r9/sgWpfwb7+MwO9cJVpx/iFv9NLOR2nPMuYmD+rZ9+e+HA7txsS
yvOXtVp4jfuWk0FaTM1kiKA210lHoy4q7enSWErcF0tj1+KTRAQVaQ/10YgkYcNh
pQVJvzuIzcfa0pSpoLf+58i3m1tDBgBnxFR7xShclShmsIo8XVLeRluD5wywIBnQ
IkB0MmLQGgN8S09iz7aevDNRj8Jjbr+A0Oisb0DFZm96+HaHYZ7/o7pGwXNHqHf8
DnBaWev50w6RqewKv2BOBkuKc3O+ozwxFG7jkdvD7/BGWC/cbyZ3+jxDwdbG4Tkz
h1qlG7+OeaSvQ/PHFaOFoIhdhbXz+IKIskjbILiGWVGzavDJbeXfu1vIH6KUFg+y
5GjzUcIq7cIuCB+WuR3s8G/MzX1TRcmO2nbf/HuEHwD7yBXLxJ5TqYrWRAquAo4z
81ZqsUGd5PZ2UFTLLaPQPfOdwW6KvK5W
=f9Da
-----END PGP SIGNATURE-----