Source: cups Version: 2.4.18-1 X-Debbugs-CC: [email protected] Severity: important Tags: security upstream
Hi, The following vulnerability was published for cups. CVE-2026-107888[0]: | OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference | in cupsdCheckJobs() when a job marked job-held-on-create refers to a | temporary printer that has been automatically deleted. Temporary- | printer cleanup can remove the destination without canceling its | held jobs, and the scheduler dereferences the NULL result of | cupsdFindDest() while checking holding_new_jobs. This terminates | cupsd and interrupts all queues managed by that process. In some | plausible scenarios, an unprivileged submission can trigger this. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-107888 https://www.cve.org/CVERecord?id=CVE-2026-107888 [1] https://github.com/OpenPrinting/cups/security/advisories/GHSA-qqm8-4q5h-jg55 [2] https://github.com/OpenPrinting/cups/commit/c5fc041ca0a211f8e69854907be7b55f56955659 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
