Integer overflow in kitty - CVE-2026-33642
Published: September 22, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service, disclose sensitive information, or corrupt heap memory.
The vulnerability exists due to integer overflow in the handle_compose_command() bounds check in kitty/graphics.c when processing crafted graphics escape sequences. A remote attacker can send crafted graphics escape sequences to a kitty terminal to cause a denial of service, disclose sensitive information, or corrupt heap memory.
No user interaction or non-default configuration is required.
Affected software
Debian Linux
kitty (Debian package)
How to mitigate CVE-2026-33642
kitty (Debian package) - update to 0.41.1-2+deb13u1