USN-8442-1: kitty vulnerabilities

Publication date

17 June 2026

Overview

Several security issues were fixed in kitty.


Packages

  • kitty - The fast, feature-rich, GPU based terminal emulator

Details

It was discovered that kitty incorrectly handled certain image data. An
attacker able to write to the terminal's input could possibly use this
issue to cause kitty to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-33633)

It was discovered that kitty incorrectly handled certain graphics commands.
An attacker able to write escape sequences to a kitty terminal could
possibly use this issue to cause kitty to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2026-33642)

It was discovered that kitty incorrectly handled certain image data. An
attacker able to write to the terminal's input could possibly use this
issue to cause kitty to crash, resulting in a denial of service, or
possibly execute arbitrary code. (CVE-2026-33633)

It was discovered that kitty incorrectly handled certain graphics commands.
An attacker able to write escape sequences to a kitty terminal could
possibly use this issue to cause kitty to crash, resulting in a denial of
service, or possibly execute arbitrary code. (CVE-2026-33642)

Update instructions

After a standard system update you need to restart kitty to make all the necessary changes.

Learn more about how to get the fixes.

The problem can be corrected by updating your system to the following package versions:

Ubuntu Release Package Version
26.04 LTS resolute kitty –  0.45.0-1ubuntu0.1~esm1  
kitty-shell-integration –  0.45.0-1ubuntu0.1~esm1  
25.10 questing kitty –  0.41.1-2+deb13u1build0.25.10.1
kitty-shell-integration –  0.41.1-2+deb13u1build0.25.10.1
24.04 LTS noble kitty –  0.32.2-1ubuntu0.4+esm1  
kitty-shell-integration –  0.32.2-1ubuntu0.4+esm1  
22.04 LTS jammy kitty –  0.21.2-1ubuntu0.22.04.1+esm1  
20.04 LTS focal kitty –  0.15.0-1ubuntu0.2+esm1  

Reduce your security exposure

Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.


Have additional questions?

Talk to a member of the team ›