logo

Critical Command Injection Vulnerability in Fedora's perl-GD Library

ID: ce0f87ba-19cd-587c-a7d7-39fb9a876466

STIX ID: report--ce0f87ba-19cd-587c-a7d7-39fb9a876466

Feed Name: ThreatCluster

Threat Score
70/100

Date Published: 2026-06-19

Date Updated: 2026-06-23

...
...

A critical command-injection vulnerability (CVE-2026-11526) was discovered in the perl-GD library used by Fedora 43 and 44 that can enable arbitrary command execution via the two-argument open() call. Patches were released on June 9, 2026 and administrators are urged to update their systems via dnf immediately to mitigate potential exploitation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.