GNU released gzip 1.15, a stable update containing 119 commits since version 1.14 and addressing multiple long-standing flaws. Fixes include a race condition that could make gzip delete the wrong file when an ancestor directory is renamed concurrently, use of uninitialized memory when processing malformed input, and a buffer overflow triggered by .lzh decompression following .Z decompression.
The release also corrects .lzh decompression corruption, improves recognition of PKZIP signatures in streamed ZIP data and handling of unusual filename characters, and resolves temporary-file races in some utilities on platforms lacking mktemp. GNU provides signed source archives and SHA-256/SHA3-256 checksums for verification; the update also changes locale handling for filename quoting and removes support for several legacy platforms.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
GNU gzip 1.15 was released as a stable version, succeeding gzip 1.14. The release incorporated 119 commits and fixed multiple long-standing defects, including a wrong-file deletion race, uninitialized-memory handling of malformed input, an .lzh-related buffer overflow, decompression corruption, streamed ZIP handling, and temporary-file races.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.