Fedora Tig Command Injection Vulnerability Fixed in Multiple Versions

Fedora Tig Command Injection Vulnerability Fixed in Multiple Versions

First seen 17 Jun 2026, 15:59 UTC Linuxsecurity 96% similarity 30.9

Article Content

Browse articles
ThreatCluster

On June 15, 2026, a command injection vulnerability affecting version 2.6.0 of the Tig tool was patched in Fedora 43 and Fedora 44. The vulnerability could allow unauthorized command execution through the editor interface. The updates, released by Steve Traylen, resolve the issue and upgrade Tig to version 2.6.1. Users are advised to apply the updates using the 'dnf' package manager. The vulnerability was tracked under the issue number #1432 and resolved in both Fedora distributions. The updates were published on June 17, 2026, with specific advisories for each version. This incident highlights the importance of timely software updates to mitigate security risks.

Key Points: • Command injection vulnerability fixed in Tig for Fedora 43 and 44. • Affected version 2.6.0; patched to version 2.6.1 on June 15, 2026. • Users should update using 'dnf' to ensure security.

ThreatCluster AI How this analysis works

Timeline

2026-06-15
Patch released for Tig command injection vulnerability
Steve Traylen updated Tig to version 2.6.1, fixing a command injection vulnerability in version 2.6.0.
Linuxsecurity
2026-06-17
Fedora Update Notification issued
Fedora issued notifications for the updates to Tig in both Fedora 43 and 44, urging users to upgrade.
Linuxsecurity

Community

Browse all →

Tracked Entities in This Story