{"schema_version": "1.7.0", "id": "RLSA-2026:61623", "modified": "2026-09-01T06:12:22.958086Z", "published": "2026-09-01T06:05:33.619213Z", "upstream": ["CVE-2026-41991", "CVE-2026-41992"], "summary": "Moderate: gzip security update", "details": "The gzip packages contain the gzip (GNU zip) data compression utility. gzip is used to compress regular files. It replaces them with files containing the .gz extension, while retaining ownership modes, access, and modification times.\n\nSecurity Fix(es):\n\n* gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility (CVE-2026-41991)\n\n* gzip: gzip: Information disclosure via global buffer overflow in LZH decompression (CVE-2026-41992)\n\nFor more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.", "severity": [{"type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H"}], "affected": [{"package": {"ecosystem": "Rocky Linux:9", "name": "gzip", "purl": "pkg:rpm/rocky-linux/gzip?distro=rocky-linux-9&epoch=0"}, "ranges": [{"type": "ECOSYSTEM", "events": [{"introduced": "0"}, {"fixed": "0:1.12-2.el9_8"}], "database_specific": {"yum_repository": "BaseOS"}}]}], "references": [{"type": "ADVISORY", "url": "https://errata.rockylinux.org/RLSA-2026:61623"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494158"}, {"type": "REPORT", "url": "https://bugzilla.redhat.com/show_bug.cgi?id=2494159"}, {"type": "ADVISORY", "url": "https://access.redhat.com/errata/RHSA-2026:61623"}], "credits": [{"name": "Rocky Enterprise Software Foundation"}, {"name": "Red Hat"}], "database_specific": {"license": "CC-BY-4.0", "license_url": "https://creativecommons.org/licenses/by/4.0/", "source_advisory": "RHSA-2026:61623"}}