CVE-2026-33633

EUVD-2026-30964
Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash kitty immediately. The vulnerability is triggered by a single APC graphics protocol command with a PNG format declaration (f=100) whose payload exceeds twice the initial buffer capacity. The overflow is attacker-controlled in both length and content, causing DoS and potentially escalation to RCE itself. This issue has been fixed in version 0.47.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 29.79%
Affected Products (NVD)
VendorProductVersion
kovidgoyalkitty
𝑥
< 0.47.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
kitty
bookworm
vulnerable
bullseye
vulnerable
bullseye (security)
vulnerable
forky
0.48.2-1
fixed
sid
0.48.2-1
fixed
trixie
0.41.1-2+deb13u1
fixed
trixie (security)
0.41.1-2+deb13u2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
kitty
focal
Fixed 0.15.0-1ubuntu0.2+esm1
released
jammy
Fixed 0.21.2-1ubuntu0.22.04.1+esm1
released
noble
Fixed 0.32.2-1ubuntu0.4+esm1
released
questing
Fixed 0.41.1-2+deb13u1build0.25.10.1
released
resolute
Fixed 0.45.0-1ubuntu0.1~esm1
released