CVE detail
CVE-2026-11623
A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. Such manipulation leads to use after free. Local access is required to approach this attack. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. Upgrading to version 3.7-rc is able to address this issue. The name of the patch is fc6d94a9f8a593bd8b7031650802084385d4ee03. The affected component should be upgraded.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 8.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://vuldb.com/vuln/369303/ctivuldb.com
No excerpt available.
Exploitvuldb.comJun 9, 2026, 5:16 AM - https://vuldb.com/vuln/369303vuldb.com
No excerpt available.
Exploitvuldb.comJun 9, 2026, 5:16 AM - https://vuldb.com/submit/835623vuldb.com
No excerpt available.
Exploitvuldb.comJun 9, 2026, 5:16 AM - https://vuldb.com/cve/CVE-2026-11623vuldb.com
No excerpt available.
Exploitvuldb.comJun 9, 2026, 5:16 AM No excerpt available.
Exploitgithub.comJun 9, 2026, 5:16 AMNo excerpt available.
Exploitgithub.comJun 9, 2026, 5:16 AM- https://github.com/tmux/tmux/github.com
No excerpt available.
Exploitgithub.comJun 9, 2026, 5:16 AM No excerpt available.
Exploitgist.github.comJun 9, 2026, 5:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-16367CVSS 10.0 · Critical
Sandbox escape due to invalid pointer in the Disability Access APIs component. This vulnerability was fixed in Firefox 153 and Thunderbird 153.
- CVE-2026-15194CVSS 1.9 · Low
A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/context.c of the component AMF. Performing a manipulation res…
- CVE-2026-14788CVSS 1.9 · Low
A security vulnerability has been detected in radareorg radare2 up to 6.1.6. Affected by this vulnerability is the function r_core_bin_load of the file libr/core/cfile.c. Such man…
- CVE-2026-14760CVSS 1.9 · Low
A weakness has been identified in radareorg radare2 up to 6.1.6. Impacted is the function r_core_seek_arch_bits of the file libr/core/disasm.c of the component regprofile Handler.…
- CVE-2026-43740CVSS 6.5 · Medium
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web c…
- CVE-2026-43716CVSS 6.5 · Medium
The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web c…