Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3269-1

Опубликовано: 27 июл. 2026
Источник: suse-cvrf

Описание

Security update for gzip

This update for gzip fixes the following issue:

  • CVE-2026-41991: insecure temporary file handling in the gzexe utility when the mktemp utility is not available in the user's PATH (bsc#1269622).

Список пакетов

Container bci/bci-init:latest
gzip-1.10-150200.13.1
Container bci/bci-sle15-kernel-module-devel:latest
gzip-1.10-150200.13.1
Container bci/spack:latest
gzip-1.10-150200.13.1
Container suse/kiosk/pulseaudio:latest
gzip-1.10-150200.13.1
Container suse/kiosk/tigervnc-x11vnc:latest
gzip-1.10-150200.13.1
Container suse/kiosk/xorg:latest
gzip-1.10-150200.13.1
Container suse/ltss/sle15.4/sle15:latest
gzip-1.10-150200.13.1
Container suse/ltss/sle15.5/sle15:latest
gzip-1.10-150200.13.1
Container suse/ltss/sle15.6/sle15:latest
gzip-1.10-150200.13.1
Container suse/postgres:16
gzip-1.10-150200.13.1
Container suse/postgres:16.14
gzip-1.10-150200.13.1
Container suse/postgres:17
gzip-1.10-150200.13.1
Container suse/postgres:17.10
gzip-1.10-150200.13.1
Container suse/postgres:latest
gzip-1.10-150200.13.1
Container suse/sle-micro-rancher/5.3:latest
gzip-1.10-150200.13.1
Container suse/sle-micro-rancher/5.4:latest
gzip-1.10-150200.13.1
Container suse/sle-micro/5.5/toolbox:latest
gzip-1.10-150200.13.1
Container suse/sle-micro/5.5:latest
gzip-1.10-150200.13.1
Container suse/sle-micro/base-5.5:latest
gzip-1.10-150200.13.1
Container suse/sle-micro/kvm-5.5:latest
gzip-1.10-150200.13.1
Container suse/sle-micro/rt-5.5:latest
gzip-1.10-150200.13.1
Container suse/sle15:latest
gzip-1.10-150200.13.1
Container third-party/amd/amdgpu-driver:sles-15.7-30.20.1
gzip-1.10-150200.13.1
Container third-party/amd/amdgpu-driver:sles-15.7-30.30.4
gzip-1.10-150200.13.1
Container third-party/amd/amdgpu-driver:sles-15.7-31.10
gzip-1.10-150200.13.1
Container third-party/amd/amdgpu-driver:sles-15.7-31.20
gzip-1.10-150200.13.1
Container third-party/amd/amdgpu-driver:sles-15.7-31.30
gzip-1.10-150200.13.1
Container third-party/nvidia/driver:550-sles15.7
gzip-1.10-150200.13.1
Container third-party/nvidia/driver:570-sles15.7
gzip-1.10-150200.13.1
Container third-party/nvidia/driver:575-sles15.7
gzip-1.10-150200.13.1
Container third-party/nvidia/driver:580-sles15.7
gzip-1.10-150200.13.1
Container third-party/nvidia/driver:590-sles15.7
gzip-1.10-150200.13.1
Container third-party/nvidia/driver:595-sles15.7
gzip-1.10-150200.13.1
SUSE Linux Enterprise High Performance Computing 15 SP4-ESPOS
gzip-1.10-150200.13.1
SUSE Linux Enterprise High Performance Computing 15 SP4-LTSS
gzip-1.10-150200.13.1
SUSE Linux Enterprise High Performance Computing 15 SP5-ESPOS
gzip-1.10-150200.13.1
SUSE Linux Enterprise High Performance Computing 15 SP5-LTSS
gzip-1.10-150200.13.1
SUSE Linux Enterprise Micro 5.3
gzip-1.10-150200.13.1
SUSE Linux Enterprise Micro 5.4
gzip-1.10-150200.13.1
SUSE Linux Enterprise Micro 5.5
gzip-1.10-150200.13.1
SUSE Linux Enterprise Module for Basesystem 15 SP7
gzip-1.10-150200.13.1
SUSE Linux Enterprise Server 15 SP4-LTSS
gzip-1.10-150200.13.1
SUSE Linux Enterprise Server 15 SP5-LTSS
gzip-1.10-150200.13.1
SUSE Linux Enterprise Server 15 SP6-LTSS
gzip-1.10-150200.13.1
SUSE Linux Enterprise Server for SAP Applications 15 SP4
gzip-1.10-150200.13.1
SUSE Linux Enterprise Server for SAP Applications 15 SP5
gzip-1.10-150200.13.1
SUSE Linux Enterprise Server for SAP Applications 15 SP6
gzip-1.10-150200.13.1

Описание

GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user's PATH, gzexe falls back to constructing a temporary file path based solely on the process ID (PID). This predictable filename is created without exclusive access or existence checks. A local attacker can pre-create the predicted temporary file path as a symbolic link pointing to an arbitrary file writable by the victim. When gzexe runs, it follows the symlink and overwrites the target file, resulting in a time-of-check to time-of-use (TOCTOU) condition that allows arbitrary file overwrite. This issue has been fixed in the commit 4e6f8b24ab823146ab8776f0b7fe486ab34d4269


Затронутые продукты
Container bci/bci-init:latest:gzip-1.10-150200.13.1
Container bci/bci-sle15-kernel-module-devel:latest:gzip-1.10-150200.13.1
Container bci/spack:latest:gzip-1.10-150200.13.1
Container suse/kiosk/pulseaudio:latest:gzip-1.10-150200.13.1

Ссылки