CVE-2026-11623
Publication date 9 June 2026
Last updated 9 June 2026
Ubuntu priority
Cvss 3 Severity Score
Description
A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. Such manipulation leads to use after free. Local access is required to approach this attack. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. Upgrading to version 3.7-rc is able to address this issue. The name of the patch is fc6d94a9f8a593bd8b7031650802084385d4ee03. The affected component should be upgraded.
Status
| Package | Ubuntu Release | Status |
|---|---|---|
| tmux | 26.04 LTS resolute |
Needs evaluation
|
| 25.10 questing |
Needs evaluation
|
|
| 24.04 LTS noble |
Needs evaluation
|
|
| 22.04 LTS jammy |
Needs evaluation
|
|
| 20.04 LTS focal |
Needs evaluation
|
|
| 18.04 LTS bionic |
Needs evaluation
|
|
| 16.04 LTS xenial |
Needs evaluation
|
|
| 14.04 LTS trusty |
Needs evaluation
|
Severity score breakdown
| Parameter | Value |
|---|---|
| Base score |
|
| Attack vector | Local |
| Attack complexity | High |
| Privileges required | Low |
| User interaction | None |
| Scope | Unchanged |
| Confidentiality | Low |
| Integrity impact | Low |
| Availability impact | Low |
| Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L |
References
Other references
- https://www.cve.org/CVERecord?id=CVE-2026-11623
- https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03 (3.7-rc)
- https://gist.github.com/XlabAITeam/f0d9952595f795129a3258ba73bbc3cb
- https://github.com/tmux/tmux/
- https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03
- https://github.com/tmux/tmux/releases/tag/3.7-rc
- https://vuldb.com/cve/CVE-2026-11623
- https://vuldb.com/submit/835623
- https://vuldb.com/vuln/369303
- https://vuldb.com/vuln/369303/cti