Description: Split privileged ServerSetSettings from unprivileged CUPS 
operations
 Keep the existing cups-pk-helper D-Bus mechanism running as cups-pk-helper
 and retain its Polkit authorization check. Add a root-only D-Bus backend for
 configuration writes; it accepts requests only from the frontend service 
account
 and returns backend errors to callers.
 .
 Install a higher-priority Polkit local-authority policy that overrides Ubuntu's
 broad active-session allow rule for ServerSetSettings only, requiring
 administrator authentication while leaving other helper actions unchanged.

** Patch removed: "root-server-settings-backend.patch"
   
https://bugs.launchpad.net/ubuntu/+source/cups-pk-helper/+bug/2167414/+attachment/6000497/+files/root-server-settings-backend.patch

** Patch added: "root-server-settings-backend.patch"
   
https://bugs.launchpad.net/ubuntu/+source/cups-pk-helper/+bug/2167414/+attachment/6000498/+files/root-server-settings-backend.patch

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2167414

Title:
  ServerSetSettings fails after CVE-2025-61915: non-root cups-pk-helper
  cannot PUT cupsd.conf

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/cups-pk-helper/+bug/2167414/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to