Skip to content
Fedora tmux Use-After-Free Vulnerability Advisory

Fedora tmux Use-After-Free Vulnerability Advisory

First seen 10 Jul 2026, 06:55 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 1, 2026 at 14:16 UTC
  • •CVE-2026-11623 affects Fedora tmux versions 3.6b to 3.7.
  • •The vulnerability is classified as low severity with a CVSS score of 2.0.
  • •Users are urged to upgrade to the latest tmux version to avoid potential risks.

Fedora has issued advisories for tmux versions 3.6b to 3.7, addressing a severe use-after-free vulnerability identified as CVE-2026-11623. This flaw affects users of Fedora 43 and 44, allowing potential exploitation through crafted input. The vulnerability was publicly disclosed on June 9, 2026, with a CVSS score categorized as low. The tmux updates introduce floating panes and various enhancements, but the advisory emphasizes that many features remain limited. Users are advised to upgrade to the latest version to mitigate risks. The issue has been patched, and no has been reported as of now.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Timeline

2026-06-09
CVE-2026-11623 published
Fedora disclosed a low severity use-after-free vulnerability in tmux affecting versions 3.6b to 3.7.
Linuxsecurity

More articles in this cluster (2)

Following this threat?

Track CVE-2026-11623 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

Which versions are affected?
Fedora tmux versions 3.6b to 3.7 are affected by CVE-2026-11623.
Is there an active exploit for this vulnerability?
No active exploitation has been reported for CVE-2026-11623 as of now.
What should users do to protect themselves?
Users should upgrade to the latest version of tmux to mitigate the vulnerability.