Home

Description

A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. Such manipulation leads to use after free. Local access is required to approach this attack. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. Upgrading to version 3.7-rc is able to address this issue. The name of the patch is fc6d94a9f8a593bd8b7031650802084385d4ee03. The affected component should be upgraded.

PUBLISHED Reserved 2026-06-08 | Published 2026-06-09 | Updated 2026-06-09 | Assigner VulDB




LOW: 2.0CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
MEDIUM: 4.5CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
MEDIUM: 4.5CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
3.5AV:L/AC:H/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C

Problem types

Use After Free

Memory Corruption

Timeline

2026-06-08:Advisory disclosed
2026-06-08:VulDB entry created
2026-06-08:VulDB entry last update

Credits

XlabAI (VulDB User) reporter

References

vuldb.com/vuln/369303 (VDB-369303 | tmux image.c image_free use after free) vdb-entry technical-description

vuldb.com/vuln/369303/cti (VDB-369303 | CTI Indicators (IOB, IOC, IOA)) signature permissions-required

vuldb.com/cve/CVE-2026-11623 (CVE-2026-11623 | CVE Analysis and Report) third-party-advisory

vuldb.com/submit/835623 (Submit #835623 | tmux <= 3.6a Use After Free) third-party-advisory

gist.github.com/XlabAITeam/f0d9952595f795129a3258ba73bbc3cb exploit

github.com/...ommit/fc6d94a9f8a593bd8b7031650802084385d4ee03 patch

github.com/tmux/tmux/releases/tag/3.7-rc patch

github.com/tmux/tmux/ product

cve.org (CVE-2026-11623)

nvd.nist.gov (CVE-2026-11623)

Download JSON