A vulnerability marked as problematic has been reported in GNU gzip up to 1.14. This issue affects some unknown processing of the component LZH Decoder. The manipulation leads to buffer over-read.

This vulnerability is traded as CVE-2026-41992. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to install a patch to address this issue.