PT-2026-53255 · Gnu+3 · Gzip+3

·

CVE-2026-41991

·

Published

2026-06-29

·

Updated

2026-09-09

CVSS v3.1

4.7

Medium

VectorAV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions GNU gzip (affected versions not specified)
Description The gzexe utility handles temporary files insecurely. If the mktemp utility is missing from the user's PATH, gzexe generates a temporary file path using only the process ID (PID). Because this filename is predictable and created without existence checks or exclusive access, a local attacker can create a symbolic link at that path pointing to any file the victim has permission to write. This creates a time-of-check to time-of-use (TOCTOU) condition—a race condition where a system checks a condition and then uses the result, but the condition changes in between—allowing the attacker to overwrite arbitrary files.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:61623
ALSA-2026:61625
ALSA-2026:65998
CVE-2026-41991
ECHO-233F-78F2-A73B
JLSEC-2026-1264
JLSEC-2026-1265
OESA-2026-2969
OESA-2026-2970
OESA-2026-2971
OESA-2026-2972
OESA-2026-2997
OPENSUSE-SU-2026:11174-1
OPENSUSE-SU-2026:21371-1
RHSA-2026:33771
RHSA-2026:61623
RHSA-2026:61625
SUSE-SU-2026:22753-1
SUSE-SU-2026:22818-1
SUSE-SU-2026:22906-1
SUSE-SU-2026:22918-1
SUSE-SU-2026:3241-1
SUSE-SU-2026:3269-1
USN-8512-1
USN-8733-1

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Gzip