#1145629 trixie-pu: package gzip/1.13-1+deb13u1

#1145629#5
Date:
2026-08-26 03:55:05 UTC
From:
To:
Hi Release Managers,

Gzip 1.13-1+deb13u1 fixes CVE-2026-41991 and CVE-2026-41992 that have
been deemed as no-DSA-needed by security team. I'm thus proceeding with
upload approval request for next trixie point release.

Backported patches are minimally modified. The issues have been verified
and fixed in sid. The trixie build is passing standard build and autopkgtest
testsuites. All changes have been documented in the debian/changelog.

Changelog items:

  * d/p/CVE-2026-41991-a.patch, d/p/CVE-2026-41991-b.patch: use -C if
    lacking mktemp, closes: #1141442, CVE-2026-41991

  * d/p/CVE-2026-41992.patch: gzip: don’t mishandle .lzh after .Z,
    closes: #1141443, CVE-2026-41992

See attached debdiff for more info.

Milan

#1145629#12
Date:
2026-09-04 11:06:51 UTC
From:
To:
Control: tags -1 + confirmed

The former doesn't sound like affects any Debian system in practice?

Please go ahead.

Regards,

Adam

#1145629#19
Date:
2026-09-05 15:20:10 UTC
From:
To:
package release.debian.org
tags 1145629 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: gzip
Version: 1.13-1+deb13u1

Explanation: fix insecure temporary file handling issue [CVE-2026-41991]; fix buffer overflow issue [CVE-2026-41992]

#1145629#24
Date:
2026-09-05 15:20:10 UTC
From:
To:
package release.debian.org
tags 1145629 = trixie pending
thanks

Hi,

The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie.

Thanks for your contribution!

Upload details
==============

Package: gzip
Version: 1.13-1+deb13u1

Explanation: fix insecure temporary file handling issue [CVE-2026-41991]; fix buffer overflow issue [CVE-2026-41992]

#1145629#29
Date:
2026-09-12 08:05:41 UTC
From:
To:
This update was released as part of 13.7.