[CLSA-2026:1785139899] gzip: Fix of CVE-2026-41992
Type:
security
Severity:
Important
Release date:
2026-07-27 08:11:49 UTC
Description:
- CVE-2026-41992: out-of-bounds read in the LZH decoder from stale shared decompression state (left/right) reused across a .Z then .lzh file in a single gzip -d invocation
CVEs fixed:
Updated packages:
  • gzip-1.5-11.el7_9.tuxcare.els1.x86_64.rpm
    sha:b07a2b037e291be5dc13ec769bf6ed8ae653b9d531048fc44e13ae79e8b8ff06
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.