CVE-2026-41991General(gnu / gzip)

LOWCVSS 4.7 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch gnu gzip systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-377

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gzip

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
gzip

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-29: 1Mentions · 2026-07-02: 1Patch / Workaround · 2026-07-02: 1Technical Details · 2026-06-29: 1Technical Details · 2026-07-02: 106-2907-02
Signal classification2 categories
General
150.0%
Patch
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-291
General1
2026-07-021
Patch1
Full discourse2 posts
  • Daily CyberSecurity@the_yellow_fall
    Patch

    A GNU gzip vulnerability (CVE-2026-41991) lets a local attacker overwrite files through a gzexe symlink attack. Update to the patched gzip release now. #GNUgzip #gzip #CVE202641991 #CVE202641992 #gzexe #LinuxSecurity #Vulnerability http://securityonline.info/gnu-gzip-vulnerability-cve-2026-41991/

    Post summary

    The post announces a known gzip vulnerability (CVE‑2026‑41991) that permits local file overwrite through a gzexe symlink and urges users to apply the patched release.

    02073664
    12.9K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-41991 Insecure Temporary File Handling in GNU gzip gzexe Utility https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41991

    Post summary

    The entry identifies CVE‑2026‑41991 as an insecure temporary file handling flaw in GNU gzip but offers no detail on PoC, exploit tools, active exploitation, or mitigation.

    00000111
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnugzip---

Explore more