------------------------------------------------------------------------- Debian LTS Advisory DLA-4203-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Tobias Frost June 01, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : kitty Version : 0.19.3-1+deb11u1 CVE ID : CVE-2022-41322 Debian Bug : 1020582 A vulnerability has been found in kitty, a fast, featureful, GPU based terminal emulator, which possible allows arbitrary code execution. CVE-2022-41322 In Kitty before 0.26.2, insufficient validation in the desktop notification escape sequence can lead to arbitrary code execution. The user must display attacker-controlled content in the terminal, then click on a notification popup. For Debian 11 bullseye, this problem has been fixed in version 0.19.3-1+deb11u1. We recommend that you upgrade your kitty packages. For the detailed security status of kitty please refer to its security tracker page at: https://security-tracker.debian.org/tracker/kitty Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment:
signature.asc
Description: PGP signature