CVE-2026-41992Disclosure(gnu / gzip)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintains a global array that is shared across the LZ77, LZW, and LZH decompression routines and is not reinitialized between files processed in the same invocation. By decompressing a specially crafted LZW file followed by a specially crafted LZH file in a single gzip -d command, an attacker can poison the shared global state and subsequently trigger an out‑of‑bounds read in the LZH decoder. The LZH decompression logic follows stale values left in the shared array, causing reads past the end of the allocated global buffer. This issue has been fixed in commits 63dbf6b3b9e6e781df1a6a64e609b10e23969681 and e7378c2d421be6a286922374425680bbe9ad8b7d.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-126

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • gzip

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-06-29); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Vendors
Products
gzip

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-06-29: 1Mentions · 2026-09-02: 1Technical Details · 2026-06-29: 106-2909-02
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-06-291
Disclosure1
2026-09-021
General1
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-41992 Global Buffer Overflow in GNU gzip LZH Decompression via Shared State Reuse https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-41992

    Post summary

    The entry announces a Global Buffer Overflow vulnerability in GNU gzip LZH Decompression (CVE-2026-41992) with a brief description but lacks evidence of PoC, exploit, active exploitation, or patch information.

    0001092
    4.1K followersView on X
  • original だいすけ@daisuke
    General

    https://xeiaso.net/shitposts/no-way-to-prevent-this/memory-safety/CVE-2026-41992/

    Post summary

    The provided URL does not contain sufficient information to determine any actionable details about CVE-2026-41992.

    0000089
    1.8K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appgnugzip---

Explore more