Skip to content
Fedora 44 perl-GD Critical Command Injection Threat CVE-2026

Fedora 44 perl-GD Critical Command Injection Threat CVE-2026

Linuxsecurity LinuxSecurity Advisories June 19, 2026

This update fixes a command injection issue resulting from the use of the 2-argument form of open (CVE-2026-11526).

* Tue Jun 9 2026 Paul Howarth - 2.86-1 - Update to 2.86 - Fix command injection via 2-arg open() in _make_filehandle (CVE-2026-11526) * Tue Jun 2 2026 Paul Howarth - 2.85-1 - Update to 2.85 - Tolerate runtime TIFF decode failures in autodetect (GH#62) - Replace cpm with cpanm in github actions - Fixed a minor precedence bug in t/z_manifest.t

* Tue Jun 9 2026 Paul Howarth - 2.86-1 - Update to 2.86 - Fix command injection via 2-arg open() in _make_filehandle (CVE-2026-11526) * Tue Jun 2 2026 Paul Howarth - 2.85-1 - Update to 2.85 - Tolerate runtime TIFF decode failures in autodetect (GH#62) - Replace cpm with cpanm in github actions - Fixed a minor precedence bug in t/z_manifest.t

Fedora Update Notification FEDORA-2026-263adf0222 2026-06-19 00:59:07.048628+00:00 Name : perl-GD Product : Fedora 44 Version : 2.86 Release : 1.fc44 URL : Summary : Perl interface to the GD graphics library Description : This is a auto-loadable interface module for GD, a popular library for creating and manipulating PNG files. With this library you can create PNG images on the fly or modify existing files.

This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2026-263adf0222' at the command line. For more information, refer to the dnf documentation available at

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities

Attack Types (1)

Companies (1)