Executive brief
GNU gzip is a widely used tool for compressing and decompressing files. A security flaw in its 'gzexe' and 'zdiff' utilities could allow a local attacker to trick the software into overwriting important files on the system. This occurs when the tool is used on older systems where certain security safeguards are missing, potentially leading to data loss or system instability.
Technical details
A vulnerability exists in GNU gzip's gzexe and zdiff utilities due to insecure temporary file creation. When the mktemp utility is not found in the user's PATH, the scripts fall back to using a predictable temporary filename based on the process ID (PID) without using exclusive access flags or existence checks. A local attacker can exploit this by creating a symbolic link at the predicted path pointing to a target file the victim has write permissions for. When the victim runs gzexe or zdiff, the utility follows the symlink and overwrites the target file (TOCTOU). The issue is addressed in commit 4e6f8b2 by using 'set -C' (noclobber) and umask settings to ensure exclusive file creation.
Affected products
- GNU gzip <= 1.14
Timeline
- 2026-04-16: patched: Fix committed to upstream repository
- 2026-06-29: disclosed: CVE published to NVD