Gzip 1.15 patches wrong-file deletion race and memory-safety bugs in decoder
Gzip 1.15 was released on September 20, 2026, fixing a race condition that could cause the tool to delete the wrong file when another process renames a directory in the target path during compression. The release, announced by Jim Meyering on the GNU info-gnu mailing list, also resolves a locking failure on systems supporting O_PATH or O_SEARCH file flags. Several bugs in the .lzh decoder were addressed, including a buffer overflow triggered when decompressing an .lzh file after a .Z file, as well as two issues that produced corrupted output. The update additionally fixes use of uninitialized memory on malformed inputs and patches race conditions in the gzexe, zdiff, and znew helper scripts. No CVE identifiers were assigned, but the release is considered a security update given the memory-safety issues, especially for services that process untrusted archives.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in