Kovid Goyal

#8119de 57,307
36.9CVSS total
Vulnerabilidades · 6
Média
5
Crítica
1
PT-2026-98839
4.6
2026-09-25
Kitty · Kitty · CVE-2026-80430
**Nome do Software Vulnerável e Versões Afetadas** kitty versões 0.47.0 até 0.48.x **Descrição** A resolução inadequada de links no caminho de encenação da fonte de arrasto do protocolo de arrastar e soltar permite que um programa que escreva no terminal crie arquivos e diretórios fora do diretório de encenação. Isso ocorre porque a função `subdir data for drag()` em `kitty/dnd.c` resolve descendentes da árvore de itens encenados construindo uma string de caminho e abrindo-a com `safe open(path, O DIRECTORY | O RDONLY, 0)` em vez de percorrer a árvore componente por componente. Um invasor pode declarar duas entradas com o mesmo nome — primeiro um link simbólico apontando para um caminho absoluto arbitrário e, em seguida, um diretório — fazendo com que o `mkdirat()` falhe com EEXIST. O código ignora essa falha, levando a resolução de caminho subsequente a seguir o link simbólico e retornar um descritor de diretório fora do diretório de encenação. Este descritor é então passado como o argumento `dirfd` para `add payload()` e usado para todas as operações de criação subsequentes. Embora os nomes das entradas sejam sanitizados, os alvos dos links simbólicos não são validados. Arquivos são criados com O CREAT | O WRONLY | O EXCL no modo 0644, impedindo a sobrescrita de arquivos existentes, mas diretórios são criados com `mkdirat()` no modo 0755, permitindo a criação de novos diretórios intermediários em qualquer caminho gravável pelo usuário que executa a aplicação, desde que o alvo do link simbólico seja um diretório existente. **Recomendações** Atualize o kitty para a versão 0.49.0 ou posterior.
PT-2026-98931
4.6
2026-09-25
Kovid Goyal · Kitty · CVE-2026-95834
Use After Free in the drag source path of the drag and drop protocol in kitty from 0.47.0 before 0.49.0 allows a program writing to the terminal to cause the terminal to read from and write to freed heap memory, because drag remote file data() in kitty/dnd.c holds a DragRemoteItem pointer into an array it does not own, calls toplevel data for drag() or subdir data for drag(), and then continues to use that pointer. Those helpers, and add payload() and populate dir entries() which they call, report errors through the abrt() macro, which expands to cancel drag() followed by a plain return, and cancel drag() calls drag free offer(), which frees the array the pointer refers to. The helpers return void, so the caller receives no indication that the teardown happened, and proceeds to call all children complete() on the freed pointer, which dereferences it, and then to write through it. That dereference is guarded by a local flag that is set when the request carries no payload and announces no further data, which is the same condition that selects the finalisation block of add payload(), so the error paths in that block reach it: a create that fails because an entry of the same name already exists, because the client may declare two entries with one name and the create operations use O CREAT with O EXCL and symlinkat(), a mkdirat() failure other than EEXIST, and the directory entry allocation paths. Both branches reach it. In the top level branch the caller's pointer is never cleared, so clearing the owning structure's own pointers during teardown does not help. In the sub directory branch subdir data for drag() sets the caller's pointer to NULL on entry and assigns it only after its own last error path, so its own aborts leave the caller with NULL and are stopped by a null check, but it then calls add payload() with that pointer set, and an abort there leaves the caller holding a freed child node inside the item tree, which drag free offer() frees by recursion. This results in undefined behaviour in the terminal process, reachable from the byte stream of any program running in the window.