CVE-2025-58364
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Beschreibung
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme. In den Versionen 2.4.12 und früher führt eine unsichere Deserialisierung und Validierung von Druckerattributen zu einem Nullzeiger-Derefenzierungsfehler in der libcups-Bibliothek. Dies ist ein Fern-DoS-Schwachstellen, die in lokalen Subnetzen mit den Standardeinstellungen verfügbar sind. Sie kann dazu führen, dass cups und cups-browsed auf allen Maschinen im lokalen Netzwerk abstürzen, die auf Drucker hören (also standardmäßig für alle regulären Linux-Maschinen). Auf Systemen, bei denen die Schwachstelle CVE-2024-47176 (cups-filters 1.x/cups-browsed 2.x-Schwachstelle) nicht behoben wurde und der Firewall auf dem Gerät eingehende Kommunikation zum IPP-Port nicht ablehnt, und das Gerät für die öffentliche Internetverfügbarkeit konfiguriert ist, ist ein Angriffsvektor "Netzwerk" möglich. Die aktuellen Versionen von CUPS und cups-browsed-Projekten haben den Angriffsvektor "Angrenzend" in ihren Standardeinstellungen. Version 2.4.13 enthält einen Patch für CVE-2025-58364.
Metriken
Weakness-Klassen (CWE)
CWE-20Class
Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
cwe.mitre.org →CWE-476Base
NULL Pointer Dereference
The product dereferences a pointer that it expects to be valid but is NULL.
cwe.mitre.org →
Betroffene Betriebssysteme
linux
ubuntu / cupsjammy
linux
ubuntu / cupsnoble
linux
ubuntu / cupsquesting
linux
ubuntu / cupsresolute
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
Open Source
CUPS< 2.4.15
gefixt in 2.4.15
openprinting
cups2.4.13
openprinting
cups2.4.16
openprinting
cups-filters1.28.17
openprinting
cups-filters1.28.18
openprinting
libcupsfilters2.0.0 – 2.1.1
openprinting
libcupsfilters2.0.0 – 2.1.2
Quellen & Referenzen
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-4c68-qgrh-rmmqx_refsource_CONFIRM
- https://github.com/OpenPrinting/cups/commit/595d691075b1d396d2edfaa0a8fd0873a0a1f221x_refsource_MISC
- https://lists.debian.org/debian-lts-announce/2025/09/msg00013.html
- http://www.openwall.com/lists/oss-security/2025/09/11/1
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-pjv5-prqp-46rgx_refsource_CONFIRM
- https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-893j-2wr2-wrh9x_refsource_CONFIRM
- https://github.com/OpenPrinting/cups-filters/commit/50d94ca0f2fa6177613c97c59791bde568631865x_refsource_MISC
- https://github.com/OpenPrinting/cups-filters/blob/aea8d0db017e495b0204433ebdb0e86b4871094c/filter/pdftoraster.cxx#L1620x_refsource_MISC
- https://github.com/OpenPrinting/cups-filters/blob/aea8d0db017e495b0204433ebdb0e86b4871094c/filter/pdftoraster.cxx#L1880x_refsource_MISC
- https://github.com/OpenPrinting/libcupsfilters/blob/1dd86d835b27ed149b66aee1a4853d1db8a1f44c/cupsfilters/pdftoraster.cxx#L1790x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2025/11/12/2
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-v987-m8hp-phj9x_refsource_CONFIRM
- https://github.com/OpenPrinting/cups/commit/88516bf6d9e34cef7a64a704b856b837f70cd220x_refsource_MISC
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-f53q-7mxp-9gcrx_refsource_CONFIRM
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-7qx3-r744-6qv4x_refsource_CONFIRM
- https://github.com/OpenPrinting/cups/commit/e58cba9d6fceed4242980e51dbd1302cf638ab1dx_refsource_MISC
- http://www.openwall.com/lists/oss-security/2025/09/11/2
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-6qxf-7jx6-86fhx_refsource_CONFIRM
- https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-jpxg-qc2c-hgv4x_refsource_CONFIRM
- https://github.com/OpenPrinting/libcupsfilters/commit/b69dfacec7f176281782e2f7ac44f04bf9633cfax_refsource_MISC
Verknüpfte CVEs
- CVE-2026-39316
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
mediumCVSSv3 4.0 - CVE-2026-39314
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
mediumCVSSv3 4.0 - CVE-2026-34990
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
highCVSSv3 7.8 - CVE-2026-34980
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
highCVSSv3 7.5 - CVE-2026-34979
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
mediumCVSSv3 5.3 - CVE-2026-34978
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
mediumCVSSv3 6.5 - CVE-2026-27447
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
mediumCVSSv3 6.3 - CVE-2025-64503
Cups-Filters enthält Backends, Filter und andere Software, die für den Betrieb des CUPS-Druckdienstes auf Betriebssystemen erforderlich s…
mediumCVSSv3 4.0 - CVE-2025-58436
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
mediumCVSSv3 5.1 - CVE-2025-58060
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
highCVSSv3 8.0 - CVE-2025-57812
CUPS ist ein standardsbasiertes, quelloffenes Drucksystem, und `libcupsfilters` enthält den Code der Filter des ehemaligen Pakets `cups-f…
lowCVSSv3 3.7