UBUNTU-CVE-2026-41991
Dashboard / Vulnerabilities / UBUNTU-CVE-2026-41991
UBUNTU-CVE-2026-41991
Summary:
Details: GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269
References: https://ubuntu.com/security/CVE-2026-41991, https://www.cve.org/CVERecord?id=CVE-2026-41991, https://cert.pl/en/posts/2026/04/CVE-2026-41991/, https://www.gnu.org/software/gzip/, https://ubuntu.com/security/notices/USN-8512-1, https://ubuntu.com/security/notices/USN-8733-1, https://ubuntu.com/security/notices/USN-8733-2
Affected packages
Package
Name: gzip
Purl: pkg:deb/ubuntu/gzip?arch=source&distro=esm-infra-legacy%2Ftrusty
Affected ranges
Type: ECOSYSTEM
Events:
