Article

    Cyber News / Article / Vulnerabilities in gzip software

    Vulnerabilities in gzip software
    CE
    CERT Polska-2026-06-29

    Vulnerabilities in gzip software

    CERT Polska has received a report about vulnerabilities in GNU gzip software and participated in coordination of their disclosure.

    The vulnerabilityCVE-2026-41991: GNU gzip contains a vulnerability in thegzexeutility related to insecure temporary file handling. When themktemputility is not available in the user’s PATH,gzexefalls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. Whengzexeruns, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.

    This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269.

    The vulnerabilityCVE-2026-41992: GNU gzip contains a global buffer overflow vulnerability in theLZHdecompression logic caused by improper reuse of shared global state between different decompression formats within a single execution.GNU gzipmaintains a global array that is shared across theLZ77,LZW, andLZHdecompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially craftedLZWfile followed by a specially craftedLZHfile in a singlegzip -dcommand, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in theLZHdecoder. TheLZHdecompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer.

    This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d.

    We thank Michal Majchrowicz and Marcin Wyczechowski (AFINE) for the responsible vulnerability report. For the report of incomplete the patch for CVE-2026-41992, we thank Elias Hasas (@zer0d4y5).

    Original source