Bug 2541404 (CVE-2026-95832)
| Summary: | CVE-2026-95832 kitty: Reflected unknown field names in the kitty colour control escape code allow command execution in the user's shell | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | jcantril, rhel-process-autobot, rojacob, watson-tool-maintainers |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in kitty. This vulnerability allows an application writing output to the terminal to execute arbitrary commands in the user's shell. The issue occurs because the color control escape code handler echoes unrecognized field names back into the terminal's input stream without adequate sanitization. Consequently, the reflected data is processed by the shell as user input, allowing unauthorized command execution with the privileges of the active user.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
| Bug Depends On: | 2542547, 2542548, 2542533, 2542534, 2542535, 2542536, 2542537 | ||
| Bug Blocks: | |||
|
Description
OSIDB Bzimport
2026-09-25 13:10:42 UTC
|