Hi all!

due heavy load of security reports and long queues of Github CNA we had re-evaluate our security policies to the following points:

- we do embargoes for vulnerabilities with CVSS score > 7.0, which will be announced on proper security lists

- we use GHSA ids for vulnerabilities under CVSS score 7.0, and we commit the fix and publish the advisory without embargo - this point was applied because of long queue for getting CVE id and severity of fixes was not severe to go via full embargo process. Those vulnerabilities will be repeated on oss-security list right before new version release, with links to the relevant advisories where are links to the patching commits. Some of the issues might have CVE ids, because the id was assigned

For more details check SECURITY.md in CUPS project.

The new soon-to-be version 2.4.20 includes fixes:

  SECURITY-5.7: CVE-2026-55480: copy_model() creates a predictable PPD tempfile without O_EXCL/O_NOFOLLOW (CVE-2026-55480)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-jj94-x3qh-ffp9

  SECURITY-5.5: Unauthenticated read-only IPP attribute filter bypass in cupsd leads to persistent denial of service (and job-status forgery) (GHSA-7j85-5r23-xhvh)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-7j85-5r23-xhvh

  SECURITY-5.3: CVE-2026-61702: root-side banner file disclosure (CVE-2026-61702)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-gq9p-4w7m-2f5g

  SECURITY-4.6: CUPS: malformed IPP attribute names bypass CVE-2026-34980 mitigations (GHSA-w9hj-hq9p-m7f6)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-w9hj-hq9p-m7f6

  SECURITY-4.3: Heap out-of-bounds read in cupsUTF32ToUTF8() via missing source-length bound — reachable from SNMP supply-description parsing (backend/snmp-supplies.c) (CVE-2026-87875)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-559w-7676-3xrq

  SECURITY-4.1: NULL pointer dereference in cupsdCheckJobs crashes cupsd after temporary printer deletion (GHSA-qqm8-4q5h-jg55)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-qqm8-4q5h-jg55

  SECURITY-3.4: `job-presets-supported` member values allow PPD filter injection and code execution as lp under some circumstances (GHSA-fw7q-ww8w-phx8)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-fw7q-ww8w-phx8

  SECURITY-3.3: Unauthenticated Denial of Service in cupsd via Repeated IPP Group Tags (GHSA-wjc4-qhjr-5m5x)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-wjc4-qhjr-5m5x

  SECURITY-3.3: CUPS ipp backend status-line injection can update queue PPD and lead to conditional RCE as lp via foomatic-rip (CVE-2026-55453)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-7hqf-mfhx-7r3v

  SECURITY-3.0: ZDI-CAN-33033: OpenPrinting CUPS Scheduler Configuration Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability (GHSA-gj33-wxpv-6fgg)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-gj33-wxpv-6fgg

  SECURITY-3.0: CVE-2026-27447 follow-up: remaining case-insensitive username matching in scheduler side paths (CVE-2026-87876)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-r8jp-q6fh-g5r2

  SECURITY-2.5: Argument injection in mailto notifier allows unauthenticated remote code execution (CVE-2026-105326)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-r4wf-366f-f6g3

  SECURITY-2.5: CUPS fax option values bypass the CVE-2026-34980 control-character sanitizer (incomplete fix) (CVE-2026-55467)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-69qc-prxg-h2c7

  SECURITY-2.3: Double-free in cupsd class management via CUPS-Add-Modify-Class and CUPS-Delete-Class (GHSA-pwg4-pv39-8c22)
https://github.com/OpenPrinting/cups/security/advisories/GHSA-pwg4-pv39-8c22


Have a nice day!


Zdenek

--
Zdenek Dohnal
Senior Software Engineer
Red Hat, BRQ-TPBC

Reply via email to