{"id":"UBUNTU-CVE-2026-41991","details":"GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269","modified":"2026-09-23T14:41:48.644496748Z","published":"2026-06-29T12:16:00Z","related":["USN-8512-1","USN-8733-1","USN-8733-2"],"upstream":["CVE-2026-41991"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-41991"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-41991"},{"type":"REPORT","url":"https://cert.pl/en/posts/2026/04/CVE-2026-41991/"},{"type":"REPORT","url":"https://www.gnu.org/software/gzip/"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8512-1"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8733-1"},{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-8733-2"}],"affected":[{"package":{"name":"gzip","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/gzip?arch=source&distro=esm-infra-legacy%2Ftrusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6-3ubuntu1+esm2"}]}],"versions":["1.6-2ubuntu1","1.6-3ubuntu1","1.6-3ubuntu1+esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.6-3ubuntu1+esm2","binary_name":"gzip"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41991.json"}},{"package":{"name":"gzip","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/gzip?arch=source&distro=esm-infra-legacy%2Fxenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6-4ubuntu1+esm2"}]}],"versions":["1.6-4ubuntu1","1.6-4ubuntu1+esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"1.6-4ubuntu1+esm2","binary_name":"gzip"}],"availability":"Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41991.json"}},{"package":{"name":"gzip","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/gzip?arch=source&distro=esm-infra%2Fbionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.6-5ubuntu1.2+esm1"}]}],"versions":["1.6-5ubuntu1","1.6-5ubuntu1.1","1.6-5ubuntu1.2"],"ecosystem_specific":{"binaries":[{"binary_version":"1.6-5ubuntu1.2+esm1","binary_name":"gzip"},{"binary_name":"gzip-win32","binary_version":"1.6-5ubuntu1.2+esm1"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41991.json"}},{"package":{"name":"gzip","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/gzip?arch=source&distro=esm-infra%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10-0ubuntu4.1+esm1"}]}],"versions":["1.10-0ubuntu3","1.10-0ubuntu4","1.10-0ubuntu4.1"],"ecosystem_specific":{"binaries":[{"binary_name":"gzip","binary_version":"1.10-0ubuntu4.1+esm1"},{"binary_name":"gzip-win32","binary_version":"1.10-0ubuntu4.1+esm1"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41991.json"}},{"package":{"name":"gzip","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/gzip?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.10-4ubuntu4.2"}]}],"versions":["1.10-4ubuntu1","1.10-4ubuntu2","1.10-4ubuntu3","1.10-4ubuntu4","1.10-4ubuntu4.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"gzip","binary_version":"1.10-4ubuntu4.2"},{"binary_name":"gzip-win32","binary_version":"1.10-4ubuntu4.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41991.json"}},{"package":{"name":"gzip","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/gzip?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.12-1ubuntu3.2"}]}],"versions":["1.12-1ubuntu1","1.12-1ubuntu2","1.12-1ubuntu3","1.12-1ubuntu3.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_name":"gzip","binary_version":"1.12-1ubuntu3.2"},{"binary_name":"gzip-win32","binary_version":"1.12-1ubuntu3.2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41991.json"}},{"package":{"name":"gzip","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/gzip?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.13-1ubuntu3","1.13-1ubuntu4"],"ecosystem_specific":{"binaries":[{"binary_name":"gzip","binary_version":"1.13-1ubuntu4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41991.json"}},{"package":{"name":"gzip","ecosystem":"Ubuntu:26.04:LTS","purl":"pkg:deb/ubuntu/gzip?arch=source&distro=resolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.14-1~exp2ubuntu1.1"}]}],"versions":["1.13-1ubuntu4","1.13-1ubuntu5","1.14-1~exp2ubuntu1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"1.14-1~exp2ubuntu1.1","binary_name":"gzip"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-41991.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:P/PR:N/UI:P/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:N"},{"type":"Ubuntu","score":"medium"}]}