PT-2026-53256 · Gnu+3 · Gzip+3

·

CVE-2026-41992

·

Published

2026-06-29

·

Updated

2026-09-09

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions GNU gzip (affected versions not specified)
Description An issue exists in the LZH decompression logic where shared global state is improperly reused between different decompression formats during a single execution. The software maintains a global array shared across LZ77, LZW, and LZH routines that is not reinitialized between processed files. An attacker can poison this shared state by decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single command, triggering an out-of-bounds read in the LZH decoder as it follows stale values left in the shared array.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Buffer Over-read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:61623
ALSA-2026:61625
ALSA-2026:65998
AZL-91406
CVE-2026-41992
ECHO-FAD9-E6AB-E1E3
JLSEC-2026-1265
OESA-2026-2969
OESA-2026-2970
OESA-2026-2971
OESA-2026-2972
OESA-2026-2997
OPENSUSE-SU-2026:11518-1
OPENSUSE-SU-2026:21666-1
SUSE-SU-2026:23356-1
SUSE-SU-2026:23363-1
SUSE-SU-2026:23392-1
SUSE-SU-2026:3590-1
SUSE-SU-2026:3592-1
USN-8512-1
USN-8733-1

Affected Products

Linuxmint
Rocky Linux
Ubuntu
Gzip