Linuxsecurity Fedora tmux Use-After-Free Vulnerability Advisory
Article Content
- •CVE-2026-11623 affects Fedora tmux versions 3.6b to 3.7.
- •The vulnerability is classified as low severity with a CVSS score of 2.0.
- •Users are urged to upgrade to the latest tmux version to avoid potential risks.
Fedora has issued advisories for tmux versions 3.6b to 3.7, addressing a severe use-after-free vulnerability identified as CVE-2026-11623. This flaw affects users of Fedora 43 and 44, allowing potential exploitation through crafted input. The vulnerability was publicly disclosed on June 9, 2026, with a CVSS score categorized as low. The tmux updates introduce floating panes and various enhancements, but the advisory emphasizes that many features remain limited. Users are advised to upgrade to the latest version to mitigate risks. The issue has been patched, and no has been reported as of now.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track CVE-2026-11623 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
Which versions are affected?
Is there an active exploit for this vulnerability?
What should users do to protect themselves?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…