Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-41991

Опубликовано: 29 июн. 2026
Источник: nvd
CVSS3: 4.7
EPSS Низкий

Описание

GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite.

This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gnu:gzip:*:*:*:*:*:*:*:*
Версия до 1.14 (включая)

EPSS

Процентиль: 2%
0.00117
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-377

Связанные уязвимости

CVSS3: 4.7
ubuntu
около 1 месяца назад

GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269

CVSS3: 6
redhat
около 1 месяца назад

GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre‑create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time‑of‑check to time‑of‑use (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269

msrc
около 1 месяца назад

Predictable Temporary File in GNU gzip

CVSS3: 4.7
debian
около 1 месяца назад

GNU gzip contains a vulnerability in the gzexe utility related to inse ...

suse-cvrf
19 дней назад

Security update for gzip

EPSS

Процентиль: 2%
0.00117
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-377