- Package:
- release.debian.org
- Source:
- release.debian.org
- Submitter:
- Milan Kupcevic
- Date:
- 2026-09-12 08:07:39 UTC
- Severity:
- normal
- Tags:
Hi Release Managers,
Gzip 1.13-1+deb13u1 fixes CVE-2026-41991 and CVE-2026-41992 that have
been deemed as no-DSA-needed by security team. I'm thus proceeding with
upload approval request for next trixie point release.
Backported patches are minimally modified. The issues have been verified
and fixed in sid. The trixie build is passing standard build and autopkgtest
testsuites. All changes have been documented in the debian/changelog.
Changelog items:
* d/p/CVE-2026-41991-a.patch, d/p/CVE-2026-41991-b.patch: use -C if
lacking mktemp, closes: #1141442, CVE-2026-41991
* d/p/CVE-2026-41992.patch: gzip: don’t mishandle .lzh after .Z,
closes: #1141443, CVE-2026-41992
See attached debdiff for more info.
Milan
Control: tags -1 + confirmed The former doesn't sound like affects any Debian system in practice? Please go ahead. Regards, Adam
package release.debian.org tags 1145629 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: gzip Version: 1.13-1+deb13u1 Explanation: fix insecure temporary file handling issue [CVE-2026-41991]; fix buffer overflow issue [CVE-2026-41992]
package release.debian.org tags 1145629 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: gzip Version: 1.13-1+deb13u1 Explanation: fix insecure temporary file handling issue [CVE-2026-41991]; fix buffer overflow issue [CVE-2026-41992]
This update was released as part of 13.7.