Source: cups
Version: 2.4.18-1
X-Debbugs-CC: [email protected]
Severity: important
Tags: security upstream

Hi,

The following vulnerability was published for cups.

CVE-2026-107890[0]:
| OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference
| caused by repeated IPP group tags in job-creation requests. IPP
| parsing creates unnamed separator attributes with IPP_TAG_ZERO, but
| add_job() converts these separators to IPP_TAG_JOB. During job
| startup, get_options()/ipp_length() subsequently calls strlen() on a
| NULL attribute name, terminating cupsd and disrupting all queues. A
| single crafted Print-Job request can trigger the crash when the
| client can reach the scheduler and submit jobs to an accepting,
| enabled queue supporting the submitted document format. Anonymous
| submission is possible when permitted by listener and access-control
| configuration.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-107890
    https://www.cve.org/CVERecord?id=CVE-2026-107890
[1] https://github.com/OpenPrinting/cups/security/advisories/GHSA-wjc4-qhjr-5m5x
[2] 
https://github.com/OpenPrinting/cups/commit/f3fb41912e4e29dbbbe7c4afd4fe48508af21bc0

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to