Package: cups
Version: 2.4.10-3+deb13u2
Severity: grave
Tags: security

Hi Team,

I am reporting an unresolved CVE affecting the cups source package 
(specifically libcups2t64) on Debian Trixie (Debian 13), identified via a 
Prisma scanner.


  *   CVE-2026-34980 (High)

Notes:
While this vulnerability strictly requires the network-exposed cupsd daemon 
(which we have removed), the library binary libcups2t64 remains flagged by 
container image scanners. This client library is required as a dependency for 
chromium and cannot be removed.

This issue is fixed upstream in cups v2.4.17. Could you please advise on when a 
patched version will be introduced to Trixie?


Regards,
Joshua Aldwin L. Samonte
Software Prod & Plat Eng Specialist
Advanced Technology Centers in the Philippines
*: [email protected]<mailto:[email protected]>


________________________________

This message is for the designated recipient only and may contain privileged, 
proprietary, or otherwise confidential information. If you have received it in 
error, please notify the sender immediately and delete the original. Any other 
use of the e-mail by you is prohibited. Where allowed by local law, electronic 
communications with Accenture and its affiliates, including e-mail and instant 
messaging (including content), may be scanned by our systems for the purposes 
of information security, AI-powered support capabilities, and assessment of 
internal compliance with Accenture policy. Your privacy is important to us. 
Accenture uses your personal data only in compliance with data protection laws. 
For further information on how Accenture processes your personal data, please 
see our privacy statement at https://www.accenture.com/us-en/privacy-policy.
______________________________________________________________________________________

www.accenture.com

Reply via email to