Critical Command Execution Vulnerability in Config-IniFiles Affects Ubuntu and Fedora

Critical Command Execution Vulnerability in Config-IniFiles Affects Ubuntu and Fedora

First seen 20 Jun 2026, 01:55 UTC Linuxsecurity 71% similarity 72.6

Article Content

Browse articles
ThreatCluster

A critical security vulnerability has been identified in the Config-IniFiles Perl module, affecting multiple Ubuntu releases and Fedora 44. The flaw allows attackers to execute arbitrary commands or overwrite files through specially crafted input. Specifically, Ubuntu versions 26.04 LTS, 25.10, 24.04 LTS, and 22.04 LTS are impacted, as well as Fedora 44. The vulnerability is tracked as CVE-2026-11527, which was published on June 14, 2026. Users are advised to update their systems to mitigate the risk. The issue was confirmed by security notices from both Ubuntu and Fedora. The updates for Ubuntu were released on June 17, 2026, while Fedora's update was made available on June 20, 2026. This vulnerability poses a significant risk to systems using the affected versions.

Key Points: • CVE-2026-11527 allows command execution via crafted input in Config-IniFiles. • Affected systems include Ubuntu 26.04 LTS and Fedora 44, among others. • Users must update their systems immediately to mitigate potential exploits.

ThreatCluster AI How this analysis works

Timeline

2026-06-14
CVE-2026-11527 published
CVE-2026-11527 details a critical flaw in Config-IniFiles that can lead to command execution.
Linuxsecurity
2026-06-17
Ubuntu security update released
Ubuntu released updates for multiple versions to address the Config-IniFiles vulnerability.
Linuxsecurity
2026-06-20
Fedora security update released
Fedora issued an update for version 44 to fix the Config-IniFiles vulnerability.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story