rpm package
opensuse/kitty&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/kitty&distro=openSUSE%20Leap%2016.0
Vulnerabilities (6)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-46604 | Hig | 7.5 | < 0.48.2-bp160.1.1 | 0.48.2-bp160.1.1 | Jun 26, 2026 | The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset. | |
| CVE-2026-54057 | Hig | 7.8 | < 0.48.2-bp160.1.1 | 0.48.2-bp160.1.1 | Jun 12, 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into the shell's input without sanitization. Version 0.47.3 fixes the issue. | |
| CVE-2026-42851 | Hig | 7.8 | < 0.48.2-bp160.1.1 | 0.48.2-bp160.1.1 | Jun 12, 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with `cat`, a log line, an email body rendered in `less`, an issue body in a TUI, etc. — can cause kitty to e | |
| CVE-2026-42850 | Hig | 8.8 | < 0.48.2-bp160.1.1 | 0.48.2-bp160.1.1 | Jun 12, 2026 | Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A special escape code will make kitty return an error, this error is not escaped and will be correctly echoed back to the terminal | |
| CVE-2026-33642 | Cri | 9.9 | < 0.48.2-bp160.1.1 | 0.48.2-bp160.1.1 | May 19, 2026 | Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that is subject to integer wrapping, potentially leading to Hea | |
| CVE-2026-33633 | Hig | 7.5 | < 0.48.2-bp160.1.1 | 0.48.2-bp160.1.1 | May 19, 2026 | Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol |
- affected < 0.48.2-bp160.1.1fixed 0.48.2-bp160.1.1
The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.
- affected < 0.48.2-bp160.1.1fixed 0.48.2-bp160.1.1
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.3, kitty's OSC 21 (color-control) query reply reflects attacker-controlled bytes, including newlines, into the shell's input without sanitization. Version 0.47.3 fixes the issue.
- affected < 0.48.2-bp160.1.1fixed 0.48.2-bp160.1.1
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with `cat`, a log line, an email body rendered in `less`, an issue body in a TUI, etc. — can cause kitty to e
- affected < 0.48.2-bp160.1.1fixed 0.48.2-bp160.1.1
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A special escape code will make kitty return an error, this error is not escaped and will be correctly echoed back to the terminal
- affected < 0.48.2-bp160.1.1fixed 0.48.2-bp160.1.1
Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned 32-bit arithmetic that is subject to integer wrapping, potentially leading to Hea
- affected < 0.48.2-bp160.1.1fixed 0.48.2-bp160.1.1
Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol