[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index] [SECURITY] [DSA 6307-1] kitty security update To: debian-security-announce@lists.debian.org Subject: [SECURITY] [DSA 6307-1] kitty security update From: Salvatore Bonaccorso <carnil@debian.org> Date: Thu, 28 May 2026 16:03:23 +0000 Message-id: <[🔎] E1wSdCd-0000000FD3I-2yNJ@seger.debian.org> Reply-to: debian-security-announce-request@lists.debian.org -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian Security Advisory DSA-6307-1 security@debian.org https://www.debian.org/security/ Salvatore Bonaccorso May 28, 2026 https://www.debian.org/security/faq - ------------------------------------------------------------------------- Package : kitty CVE ID : CVE-2026-33633 CVE-2026-33642 Debian Bug : 1137210 Two vulnerabilities were discovered in kitty, a GPU based terminal emulator, which may result in the execution of arbitrary code or denial of service. For the stable distribution (trixie), these problems have been fixed in version 0.41.1-2+deb13u1. We recommend that you upgrade your kitty packages. For the detailed security status of kitty please refer to its security tracker page at: https://security-tracker.debian.org/tracker/kitty Further information about Debian Security Advisories, how to apply these updates to your system and frequently asked questions can be found at: https://www.debian.org/security/ Mailing list: debian-security-announce@lists.debian.org -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEERkRAmAjBceBVMd3uBUy48xNDz0QFAmoYZy5fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDQ2 NDQ0MDk4MDhDMTcxRTA1NTMxRERFRTA1NENCOEYzMTM0M0NGNDQACgkQBUy48xND z0Q6rQ/9GC5Vu5LHGJZEwI5iPNL2W+pW0xebzgwIfNRw+uB3N49vn8k8QUrkaKsd RH6z9KN6ojGa6kSTPVf1f3OEWs8+6jpmrq/MSbEQrua92lpQlVRO9H4DSwiy5/Dy AK/ev4o5tDRHeUJR6PLahSERa/4yiqavz3ibJliFm/Ww3GiBz8ykiw5FI9x3EQgb UaLquFaxYFdCyJTJYkL9c9vn/wnlzG3dkjBFfMbbMqF5bNCL0cFRYqhmgpk22Ias tgITluZHSL8EScwHCttbFbj+RlKSpOjWCfVdPG2C3dhm1CzM1acEV7GoMN02c6mK ihHCfw4pRXEvvizD0tnD5j3yuumEs713BnAea0IBudt8R2zuhycKPXaYsA3bRE7k KFIuvok1oxqfhF97nSqOqHQ/pQtEL1rp0PBzkq2njd08VpBFkL6g5d048DiZ2ZdU 0hC1oEaNhcJzz0tR0a/50O5ho9LIDrwY4N7nmJmqv2ZzEosL7RIYxL15ztUhu+gn ROTXYwE/4qzq4JM/lkiR3hjYhu8irO6VEJNfn3+zO/maHqtfplpGBgHqfMEt4Bpg qfZYdCRW4y9Wsfk+7FfXVi1PicQPUH9KbgR877DVA8pm0igWfm9Vw3vYvgnFYcM7 ehSWlVAna7NQs4FUcaFsczCNbuEIBFp4FD6O3Ss/387pfvFXu0E= =B7X5 -----END PGP SIGNATURE----- Reply to: debian-security-announce@lists.debian.org Salvatore Bonaccorso (on-list) Salvatore Bonaccorso (off-list) Prev by Date: [SECURITY] [DSA 6306-1] linux security update Next by Date: [SECURITY] [DSA 6308-1] nagios4 security update Previous by thread: [SECURITY] [DSA 6306-1] linux security update Next by thread: [SECURITY] [DSA 6308-1] nagios4 security update Index(es): Date Thread
Two critical vulnerabilities (CVE-2026-33633 and CVE-2026-33642) in the kitty terminal emulator can lead to arbitrary code execution or denial of service, with CVSS scores of 7.5 (HIGH) and 9.9 (CRITICAL) respectively. The vulnerabilities affect all versions of kovidgoyal kitty prior to version 0.47.0. The fix is to upgrade kitty to version 0.47.0.