RHSA-2026:79717MediumCVSS 6.0

Red Hat Security Advisory: Red Hat Hardened Images RPMs Security Update

Published
October 8, 2026
Last Modified
October 9, 2026

🔗 CVE IDs covered (2)

📋 Description

CVE-2026-41991 — gzip: gzip: Arbitrary file overwrite via insecure temporary file handling in gzexe utility CVE-2026-41992 — gzip: gzip: Information disclosure via global buffer overflow in LZH decompression

🎯 Affected products4

  • Red Hat Hardened Images
  • gzip-0:1.15-1.hum1@aarch64 as a component of Red Hat Hardened Images
  • gzip-0:1.15-1.hum1@src as a component of Red Hat Hardened Images
  • gzip-0:1.15-1.hum1@x86_64 as a component of Red Hat Hardened Images

✅ Remediation

For details on how to apply this update, which includes the changes described in this advisory, refer to: https://images.redhat.com/ Workaround: Ensure that the mktemp utility (provided by the coreutils package) is available in PATH when using the gzexe utility. On Red Hat Enterprise Linux, mktemp is installed by default and no additional action is needed.

🔗 References (6)