Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-80431— Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal process

Quick assessment

Affected
Kovid Goyal kitty
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 kitty 终端模拟器 0.40.0 至 0.49.0(不含 0.49.0)版本中,文本大小写协议的“自然宽度分支”存在一处越界写入漏洞。该漏洞允许向终端写入的程序向固定大小缓冲区末尾之外写入数据。 具体而言,kitty/screen.c 中的 函数在将图形簇(grapheme cluster)的每个码位追加到缓冲区时,执行 操作,但未进行任何容量检查。其中, 是通过 RAII_ListOfChars 宏在函数栈帧中声明的一个包含四个元素的 数组。因此,当 OSC 66 转义码的有效载荷中包含长度超过四个码位的

CVSS 6.8 · Medium EPSS 0.14% · P3
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-80431

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Out-of-bounds write in the kitty text sizing protocol allows termination of the terminal process
Source: CVE Program / CVE List V5
Vulnerability Description
Out-of-bounds Write in the natural width branch of the text sizing protocol in kitty from 0.40.0 before 0.49.0 allows a program writing to the terminal to write past the end of a fixed-size buffer, because screen_handle_multicell_command() in kitty/screen.c appends each codepoint of a grapheme cluster with lc.chars[lc.count++] = ch without any capacity check, while lc is declared by the RAII_ListOfChars macro as a four-element char_type array in the function's stack frame, so an OSC 66 escape code whose payload carries a grapheme cluster longer than four codepoints writes beyond that buffer, one 32-bit value per additional codepoint, in the order the codepoints appear. Where the cluster is preceded in the same payload by a sequence that causes an intermediate flush, the buffer is first migrated to the heap by ensure_space_for_chars() and the write occurs past the heap allocation instead. This results in termination of the kitty process and therefore of all its windows, tabs and child processes.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
跨界内存写
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Kovid Goyal kitty 0.40.0 ~ 0.49.0 -

II. Public POCs for CVE-2026-80431

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-80431

请登录查看更多情报信息。

Other References for CVE-2026-80431 (3)

Same Patch Batch · Kovid Goyal · 2026-09-25 · 6 CVEs total

CVE-2026-95832 9.3 CRITICAL Reflected unknown field names in the kitty colour control escape code allow command execut
CVE-2026-80432 6.0 MEDIUM Missing authorization in the kitty drag and drop protocol allows a client to obtain dragge
CVE-2026-95835 5.6 MEDIUM Missing ownership check on the shared memory object named by the kitty askpass escape code
CVE-2026-80430 4.6 MEDIUM Improper link resolution in the kitty drag and drop protocol allows a client to create fil
CVE-2026-95834 4.6 MEDIUM Use after free in the kitty drag and drop protocol when a drag source item is aborted mid-

IV. Related Vulnerabilities

V. Comments for CVE-2026-80431

No comments yet


Leave a comment