RLSA-2026:65998
Dashboard / Vulnerabilities / RLSA-2026:65998
RLSA-2026:65998
Summary: Moderate: gzip security update
Details: The gzip packages contain the gzip (GNU zip) data compression utility. gzip is used to compress regular files. It replaces them with files containing the .gz extension, while retaining ownership modes, access, and modification times. Security Fix(es): * gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility (CVE-2026-41991) * gzip: gzip: Information disclosure via global buffer overflow in LZH decompression (CVE-2026-41992) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
References: https://errata.rockylinux.org/RLSA-2026:65998, https://bugzilla.redhat.com/show_bug.cgi?id=2494158, https://bugzilla.redhat.com/show_bug.cgi?id=2494159, https://access.redhat.com/errata/RHSA-2026:65998
Affected packages
Package
Name: gzip
Purl: pkg:rpm/rocky-linux/gzip?distro=rocky-linux-8&epoch=0
Affected ranges
Type: ECOSYSTEM
Events:
