Description: Split privileged ServerSetSettings from unprivileged CUPS operations Keep the existing cups-pk-helper D-Bus mechanism running as cups-pk-helper and retain its Polkit authorization check. Add a root-only D-Bus backend for configuration writes; it accepts requests only from the frontend service account and returns backend errors to callers. . Install a higher-priority Polkit local-authority policy that overrides Ubuntu's broad active-session allow rule for ServerSetSettings only, requiring administrator authentication while leaving other helper actions unchanged.
** Patch removed: "root-server-settings-backend.patch" https://bugs.launchpad.net/ubuntu/+source/cups-pk-helper/+bug/2167414/+attachment/6000497/+files/root-server-settings-backend.patch ** Patch added: "root-server-settings-backend.patch" https://bugs.launchpad.net/ubuntu/+source/cups-pk-helper/+bug/2167414/+attachment/6000498/+files/root-server-settings-backend.patch -- You received this bug notification because you are a member of Ubuntu Bugs, which is subscribed to Ubuntu. https://bugs.launchpad.net/bugs/2167414 Title: ServerSetSettings fails after CVE-2025-61915: non-root cups-pk-helper cannot PUT cupsd.conf To manage notifications about this bug go to: https://bugs.launchpad.net/ubuntu/+source/cups-pk-helper/+bug/2167414/+subscriptions -- ubuntu-bugs mailing list [email protected] https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs
