{"id":"UBUNTU-CVE-2026-80431","details":"Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a program writing to the terminal to write past the end of a fixed-size buffer, because screen_handle_multicell_command() in kitty/screen.c appends each codepoint of a grapheme cluster with lc.chars[lc.count++] = ch without any capacity check, while lc is declared by the RAII_ListOfChars macro as a four-element char_type array in the function's stack frame, so an OSC 66 escape code whose payload carries a grapheme cluster longer than four codepoints writes beyond that buffer, one 32-bit value per additional codepoint, in the order the codepoints appear. Where the cluster is preceded in the same payload by a sequence that causes an intermediate flush, the buffer is first migrated to the heap by ensure_space_for_chars() and the write occurs past the heap allocation instead. This results in termination of the kitty process and therefore of all its windows, tabs and child processes.","modified":"2026-09-30T21:33:46Z","published":"2026-09-25T14:17:00Z","upstream":["CVE-2026-80431"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-80431"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-80431"},{"type":"REPORT","url":"https://github.com/kovidgoyal/kitty/commit/7d2fbaadcc2b1eeeef89bd875ec622b42362574b"},{"type":"REPORT","url":"https://github.com/kovidgoyal/kitty/releases/tag/v0.49.0"},{"type":"REPORT","url":"https://secur0.com/en/cna/cve-list/cve-2026-80431-kitty-text-sizing-out-of-bounds-write"}],"affected":[{"package":{"name":"kitty","ecosystem":"Ubuntu:Pro:20.04:LTS","purl":"pkg:deb/ubuntu/kitty?arch=source&distro=esm-apps%2Ffocal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.14.3-1","0.14.4-1","0.14.6-1","0.15.0-1","0.15.0-1build1","0.15.0-1ubuntu0.2","0.15.0-1ubuntu0.2+esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.15.0-1ubuntu0.2+esm1","binary_name":"kitty"},{"binary_name":"kitty-terminfo","binary_version":"0.15.0-1ubuntu0.2+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-80431.json"}},{"package":{"name":"kitty","ecosystem":"Ubuntu:Pro:22.04:LTS","purl":"pkg:deb/ubuntu/kitty?arch=source&distro=esm-apps%2Fjammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.19.3-1","0.21.2-1","0.21.2-1build1","0.21.2-1ubuntu0.22.04.1","0.21.2-1ubuntu0.22.04.1+esm1"],"ecosystem_specific":{"binaries":[{"binary_version":"0.21.2-1ubuntu0.22.04.1+esm1","binary_name":"kitty"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-80431.json"}},{"package":{"name":"kitty","ecosystem":"Ubuntu:Pro:24.04:LTS","purl":"pkg:deb/ubuntu/kitty?arch=source&distro=esm-apps%2Fnoble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.26.5-3ubuntu2","0.26.5-5ubuntu1","0.31.0-3","0.31.0-4","0.32.2-1","0.32.2-1build2","0.32.2-1build3","0.32.2-1ubuntu0.1","0.32.2-1ubuntu0.2","0.32.2-1ubuntu0.3","0.32.2-1ubuntu0.4","0.32.2-1ubuntu0.4+esm1","0.32.2-1ubuntu0.4+esm2"],"ecosystem_specific":{"binaries":[{"binary_version":"0.32.2-1ubuntu0.4+esm2","binary_name":"kitty"},{"binary_version":"0.32.2-1ubuntu0.4+esm2","binary_name":"kitty-shell-integration"},{"binary_name":"kitty-terminfo","binary_version":"0.32.2-1ubuntu0.4+esm2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-80431.json"}},{"package":{"name":"kitty","ecosystem":"Ubuntu:Pro:26.04:LTS","purl":"pkg:deb/ubuntu/kitty?arch=source&distro=esm-apps%2Fresolute"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.41.1-2","0.43.1-1","0.44.0-1","0.45.0-1","0.45.0-1build1","0.45.0-1ubuntu0.1~esm1","0.45.0-1ubuntu0.1~esm2"],"ecosystem_specific":{"binaries":[{"binary_version":"0.45.0-1ubuntu0.1~esm2","binary_name":"kitty"},{"binary_name":"kitty-shell-integration","binary_version":"0.45.0-1ubuntu0.1~esm2"},{"binary_version":"0.45.0-1ubuntu0.1~esm2","binary_name":"kitty-terminfo"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-80431.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"},{"type":"Ubuntu","score":"medium"}]}