{"id":"DEBIAN-CVE-2026-80431","details":"Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a program writing to the terminal to write past the end of a fixed-size buffer, because screen_handle_multicell_command() in kitty/screen.c appends each codepoint of a grapheme cluster with lc.chars[lc.count++] = ch without any capacity check, while lc is declared by the RAII_ListOfChars macro as a four-element char_type array in the function's stack frame, so an OSC 66 escape code whose payload carries a grapheme cluster longer than four codepoints writes beyond that buffer, one 32-bit value per additional codepoint, in the order the codepoints appear. Where the cluster is preceded in the same payload by a sequence that causes an intermediate flush, the buffer is first migrated to the heap by ensure_space_for_chars() and the write occurs past the heap allocation instead. This results in termination of the kitty process and therefore of all its windows, tabs and child processes.","modified":"2026-09-26T10:00:07.445644451Z","published":"2026-09-25T14:17:19.253Z","upstream":["CVE-2026-80431"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-80431"}],"affected":[{"package":{"name":"kitty","ecosystem":"Debian:12","purl":"pkg:deb/debian/kitty?arch=source&distro=bookworm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.26.5-5","0.30.1-1","0.31.0-1","0.31.0-2","0.31.0-3","0.31.0-4","0.32.0-1","0.32.1-1","0.32.2-1","0.33.0-2","0.33.1-1","0.34.1-1","0.35.1-1","0.35.2-1","0.36.1-1","0.36.4-1","0.36.4-2","0.36.4-3","0.37.0-1","0.38.1-1","0.39.0-1","0.39.1-1","0.40.0-1","0.41.1-1","0.41.1-2","0.42.1-1","0.42.2-1","0.43.1-1","0.44.0-1","0.45.0-1","0.45.0-2","0.46.1-1","0.46.2-1","0.47.0-1","0.47.0-2","0.47.0-3","0.47.3-1","0.47.4-1","0.48.2-1","0.48.2-1.1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-80431.json"}},{"package":{"name":"kitty","ecosystem":"Debian:13","purl":"pkg:deb/debian/kitty?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.41.1-2","0.41.1-2+deb13u1","0.41.1-2+deb13u2","0.42.1-1","0.42.2-1","0.43.1-1","0.44.0-1","0.45.0-1","0.45.0-2","0.46.1-1","0.46.2-1","0.47.0-1","0.47.0-2","0.47.0-3","0.47.3-1","0.47.4-1","0.48.2-1","0.48.2-1.1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-80431.json"}},{"package":{"name":"kitty","ecosystem":"Debian:14","purl":"pkg:deb/debian/kitty?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.41.1-2","0.42.1-1","0.42.2-1","0.43.1-1","0.44.0-1","0.45.0-1","0.45.0-2","0.46.1-1","0.46.2-1","0.47.0-1","0.47.0-2","0.47.0-3","0.47.3-1","0.47.4-1","0.48.2-1","0.48.2-1.1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-80431.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"}]}