[ALSA-2026:61623] Moderate: gzip security update
Type:
security
Severity:
moderate
Release date:
2026-09-01
Description:
The gzip packages contain the gzip (GNU zip) data compression utility. gzip is used to compress regular files. It replaces them with files containing the .gz extension, while retaining ownership modes, access, and modification times. Security Fix(es): * gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility (CVE-2026-41991) * gzip: gzip: Information disclosure via global buffer overflow in LZH decompression (CVE-2026-41992) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
Updated packages listed below:
Architecture Package Checksum
aarch64 gzip-1.12-2.el9_8.aarch64.rpm 30e1f7cb8350a12a19d22f39e8740c195e343019415d1405acf0b02278114bde
ppc64le gzip-1.12-2.el9_8.ppc64le.rpm 24f128302a19edbba1d7bcddc85578cf5de36b5e8fe0b2ccbc1a7a7b98471e86
s390x gzip-1.12-2.el9_8.s390x.rpm 3589300340e67a995cfc883b655f60880e8cf2c5fc95fe1ae3ecf4b7e0f3e660
x86_64 gzip-1.12-2.el9_8.x86_64.rpm 3ff77bcd1b314d9d5d6c2cab054172b1b3073cc3c40b9a43a2985daf910b80d2
Notes:
This page is generated automatically from Red Hat security data and has not been checked for errors. For clarification or corrections please contact the AlmaLinux Packaging Team.