EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Technical advisory

USN-8733-2: Gzip vulnerabilities

Official source
EudorIA operational summary

What it means

Priority 70/100

USN-8733-2 segnala vulnerabilità in Gzip risolvibili con aggiornamenti. Le vulnerabilità permettono a un attaccante locale di sovrascrivere file o causare un denial of service. Le versioni interessate sono Ubuntu 14.04 LTS, 18.04 LTS e 20.04 LTS. Le patch sono disponibili tramite Ubuntu Pro.

Why it matters

Le vulnerabilità possono compromettere la sicurezza di sistemi Ubuntu, permettendo a un attaccante locale di sovrascrivere file o causare un denial of service. Per le PMI italiane, la mancanza di aggiornamenti potrebbe portare a perdite di dati o interruzioni del servizio.

Potential operational benefits

  • Riduzione della superficie esposta alle vulnerabilità
  • Miglioramento della sicurezza dei sistemi Ubuntu
  • Prevenzione di accessi non autorizzati e sovrascrizioni di file
  • Riduzione del rischio di denial of service
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsPatch managementFirewall NGFW / IPSSegmentazione di reteMonitoraggio / SIEMBackup & DR
AudienceITSOCCISO
Information centre

Translation in progress

Ubuntu Security

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

USN-8733-1 fixed vulnerabilities in Gzip. This update provides the corresponding fix for Gzip on Ubuntu 14.04 LTS, Ubuntu 18.04 LTS and Ubuntu 20.04 LTS. Original advisory details: Michał Majchrowicz and Marcin Wyczechowski discovered that Gzip's gzexe utility created temporary files in an insecure manner when mktemp was unavailable. A local attacker could possibly use this issue to overwrite arbitrary files. (CVE-2026-41991) Elias Hasas, Michał Majchrowicz and Marcin Wyczechowski discovered that Gzip incorrectly handled certain compressed files. An attacker could possibly use this issue to obtain sensitive information or cause Gzip to crash, resulting in a denial of service. (CVE-2026-41992)

Source
Ubuntu Security Notices
Publishing entity
Ubuntu Security
Entity type
vendor security
Area
Global
Original language
en · translation in preparation
Publication
22/09/2026 18:04
MITRE ATT&CK
T1190, T1486
CVE
CVE-2026-41991, CVE-2026-41992
Technical scope

Affected products and versions

Verification in progress
Information not yet acquired.

The collector will check NVD and the available official vendor advisories.

Open the original source