rpm package
almalinux/gzip
pkg:rpm/almalinux/gzip
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-41992 | Hig | 7.5 | < 1.12-2.el9_8 | 1.12-2.el9_8 | Jun 29, 2026 | GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZ | |
| CVE-2026-41991 | Med | 4.7 | < 1.12-2.el9_8 | 1.12-2.el9_8 | Jun 29, 2026 | GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename | |
| CVE-2022-1271 | Hig | 8.8 | < 1.9-13.el8_5 | 1.9-13.el8_5 | Aug 31, 2022 | An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insuf |
- affected < 1.12-2.el9_8fixed 1.12-2.el9_8
GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZ
- affected < 1.12-2.el9_8fixed 1.12-2.el9_8
GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename
- affected < 1.9-13.el8_5fixed 1.9-13.el8_5
An arbitrary file write vulnerability was found in GNU gzip's zgrep utility. When zgrep is applied on the attacker's chosen file name (for example, a crafted file name), this can overwrite an attacker's content to an arbitrary attacker-selected file. This flaw occurs due to insuf