{"id":"CVE-2026-11623","summary":"tmux image.c image_free use after free","details":"A security vulnerability has been detected in tmux up to 3.6a. Affected is the function image_free of the file image.c. Such manipulation leads to use after free. Local access is required to approach this attack. This attack is characterized by high complexity. The exploitability is told to be difficult. The exploit has been disclosed publicly and may be used. Upgrading to version 3.7-rc is able to address this issue. The name of the patch is fc6d94a9f8a593bd8b7031650802084385d4ee03. The affected component should be upgraded.","modified":"2026-07-15T22:57:31.989577Z","published":"2026-06-09T03:15:12.467Z","related":["openSUSE-SU-2026:11006-1"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11623.json","cna_assigner":"VulDB","cwe_ids":["CWE-119","CWE-416"]},"references":[{"type":"WEB","url":"https://github.com/tmux/tmux/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/11xxx/CVE-2026-11623.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-11623"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-11623"},{"type":"ADVISORY","url":"https://vuldb.com/submit/835623"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/369303"},{"type":"REPORT","url":"https://vuldb.com/vuln/369303/cti"},{"type":"FIX","url":"https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03"},{"type":"FIX","url":"https://github.com/tmux/tmux/releases/tag/3.7-rc"},{"type":"EVIDENCE","url":"https://gist.github.com/XlabAITeam/f0d9952595f795129a3258ba73bbc3cb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/tmux/tmux","events":[{"introduced":"cc117b5048f77a4842820f8ebbe3a86e5c077224"},{"fixed":"fc6d94a9f8a593bd8b7031650802084385d4ee03"}],"database_specific":{"extracted_events":[{"introduced":"3.6a"},{"last_affected":"3.6a"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["3.6a"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-11623.json","vanir_signatures_modified":"2026-07-15T22:57:31Z","vanir_signatures":[{"signature_type":"Function","signature_version":"v1","source":"https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03","target":{"file":"image.c","function":"image_store"},"deprecated":false,"digest":{"function_hash":"130046608586090717648555399492418044576","length":543},"id":"CVE-2026-11623-519c3ef8"},{"digest":{"function_hash":"33953348821917947054377136663577812528","length":311},"id":"CVE-2026-11623-7287c977","signature_type":"Function","signature_version":"v1","source":"https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03","target":{"file":"image.c","function":"image_free"},"deprecated":false},{"digest":{"line_hashes":["314669577406407797017700483918507169568","196491215418247188395572508385523652790","277265925711858806171172672615886830249","163680435272177807566380771748819965554","324128932281021717943428612255569404865","306417944046175411377730481771345102693","191372580417042157643268683326053347843","91043857178984728996531983800154511193","16010132475103858660940707842669684288","162978237505394238979369440503606575404","162323491545021563200273872920008960690","259212858045621012225465770454785040438"],"threshold":0.9},"id":"CVE-2026-11623-9c283fd6","signature_type":"Line","signature_version":"v1","source":"https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03","target":{"file":"image.c"},"deprecated":false},{"signature_version":"v1","source":"https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03","target":{"file":"screen.c"},"deprecated":false,"digest":{"line_hashes":["243585262223121702710039674886383924149","3000923179617445789175872054535977200","29711898445993040853737522331114680462","207739170242782990313292220591798849296","217832254889908149913410776269651630052","57457609848185019671680868079520072570","198952428496962745394958195232519207488","215518638427316660203727282971116288209","340192084826701958680745562437380136393","262577117739396727190343479021822519413","136187601313895140158283049015381734357","303858101085851103934436317429894229634","56845470534164749181781829964780665077","198326432630672150811795620583844681853","104035809798926285813969507536274978325","125942247076040717734338385619966809793"],"threshold":0.9},"id":"CVE-2026-11623-a49a5f36","signature_type":"Line"},{"source":"https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03","target":{"function":"screen_alternate_off","file":"screen.c"},"deprecated":false,"digest":{"function_hash":"21939517085080499443374143157365858139","length":1249},"id":"CVE-2026-11623-e6e431e3","signature_type":"Function","signature_version":"v1"},{"digest":{"line_hashes":["69421044023908461307017207792481028027","46690652849006654052417588722125000429","16250653061658289049341585897524334029","217418495859114195579407146039435984293","273855056988070564765061235677078193157"],"threshold":0.9},"id":"CVE-2026-11623-f0d2a738","signature_type":"Line","signature_version":"v1","source":"https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03","target":{"file":"tmux.h"},"deprecated":false},{"signature_type":"Function","signature_version":"v1","source":"https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03","target":{"file":"screen.c","function":"screen_alternate_on"},"deprecated":false,"digest":{"function_hash":"240069217000749876820148948666368198556","length":704},"id":"CVE-2026-11623-f3f06056"}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}