RHSA-2026:33771MediumCVSS 6.0

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

Published
June 30, 2026
Last Modified
August 2, 2026

🔗 CVE IDs covered (1)

📋 Description

CVE-2026-41991 — gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility

🎯 Affected products4

  • Red Hat Hardened Images
  • gzip-main@aarch64 as a component of Red Hat Hardened Images
  • gzip-main@src as a component of Red Hat Hardened Images
  • gzip-main@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Ensure that the mktemp utility (provided by the coreutils package) is available in PATH when using the gzexe utility. On Red Hat Enterprise Linux, mktemp is installed by default and no additional action is needed.

🔗 References (6)