USN-8733-2: Gzip vulnerabilities
Ubuntu patches Gzip vulnerabilities (CVE-2026-41991) in USN-8733-2 for LTS versions, addressing insecure temp files and incorrect handling of compressed files.
Ubuntu has issued a security notice, USN-8733-2, to address vulnerabilities in the Gzip package for Ubuntu 14.04, 18.04, and 20.04 LTS versions. The update includes fixes for an insecure temporary file creation vulnerability (CVE-2026-41991) that could allow local attackers to overwrite arbitrary files, and other issues that could lead to information disclosure or denial of service. This advisory provides the corresponding fix for the original USN-8733-1 notice.
25