CVE-2026-34979
Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update
Beschreibung
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme. In Versionen 2.4.16 und früher gibt es einen heap-basierten Pufferüberlauf im CUPS-Scheduler beim Erstellen von Filteroptionstrings aus Jobattributen. Zum Zeitpunkt der Veröffentlichung sind keine öffentlichen Patches verfügbar.
Metriken
Weakness-Klassen (CWE)
CWE-122Variant
Heap-based Buffer Overflow
A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Translated2026-07-24 21:10 UTC· nvd@nist.gov
- Translation: Title: cups de OpenPrinting, Description: OpenPrinting CUPS es un sistema de impresión de código abierto para Linux y otros sistemas operativos tipo Unix. En las versiones 2.4.16 y anteriores, existe un desbordamiento de búfer basado en montículo en el planificador de CUPS al construir cadenas de opciones de filtro a partir del atributo de trabajo. Al momento de la publicación, no hay parches disponibles públicamente.
Betroffene Betriebssysteme
linux
ubuntu / cupsjammy
linux
ubuntu / cupsnoble
linux
ubuntu / cupsquesting
linux
ubuntu / cupsresolute
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
Open Source
CUPS< 2.4.15
gefixt in 2.4.15
openprinting
cups2.4.13
openprinting
cups2.4.16
openprinting
cups-filters1.28.17
openprinting
cups-filters1.28.18
openprinting
libcupsfilters2.0.0 – 2.1.1
openprinting
libcupsfilters2.0.0 – 2.1.2
Quellen & Referenzen
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-4c68-qgrh-rmmqx_refsource_CONFIRM
- https://github.com/OpenPrinting/cups/commit/595d691075b1d396d2edfaa0a8fd0873a0a1f221x_refsource_MISC
- https://lists.debian.org/debian-lts-announce/2025/09/msg00013.html
- http://www.openwall.com/lists/oss-security/2025/09/11/1
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-pjv5-prqp-46rgx_refsource_CONFIRM
- https://github.com/OpenPrinting/cups-filters/security/advisories/GHSA-893j-2wr2-wrh9x_refsource_CONFIRM
- https://github.com/OpenPrinting/cups-filters/commit/50d94ca0f2fa6177613c97c59791bde568631865x_refsource_MISC
- https://github.com/OpenPrinting/cups-filters/blob/aea8d0db017e495b0204433ebdb0e86b4871094c/filter/pdftoraster.cxx#L1620x_refsource_MISC
- https://github.com/OpenPrinting/cups-filters/blob/aea8d0db017e495b0204433ebdb0e86b4871094c/filter/pdftoraster.cxx#L1880x_refsource_MISC
- https://github.com/OpenPrinting/libcupsfilters/blob/1dd86d835b27ed149b66aee1a4853d1db8a1f44c/cupsfilters/pdftoraster.cxx#L1790x_refsource_MISC
- http://www.openwall.com/lists/oss-security/2025/11/12/2
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-v987-m8hp-phj9x_refsource_CONFIRM
- https://github.com/OpenPrinting/cups/commit/88516bf6d9e34cef7a64a704b856b837f70cd220x_refsource_MISC
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-f53q-7mxp-9gcrx_refsource_CONFIRM
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-7qx3-r744-6qv4x_refsource_CONFIRM
- https://github.com/OpenPrinting/cups/commit/e58cba9d6fceed4242980e51dbd1302cf638ab1dx_refsource_MISC
- http://www.openwall.com/lists/oss-security/2025/09/11/2
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-6qxf-7jx6-86fhx_refsource_CONFIRM
- https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-jpxg-qc2c-hgv4x_refsource_CONFIRM
- https://github.com/OpenPrinting/libcupsfilters/commit/b69dfacec7f176281782e2f7ac44f04bf9633cfax_refsource_MISC
Verknüpfte CVEs
- CVE-2026-39316
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
mediumCVSSv3 4.0 - CVE-2026-39314
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
mediumCVSSv3 4.0 - CVE-2026-34990
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
highCVSSv3 7.8 - CVE-2026-34980
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
highCVSSv3 7.5 - CVE-2026-34978
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
mediumCVSSv3 6.5 - CVE-2026-27447
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
mediumCVSSv3 6.3 - CVE-2025-64503
Cups-Filters enthält Backends, Filter und andere Software, die für den Betrieb des CUPS-Druckdienstes auf Betriebssystemen erforderlich s…
mediumCVSSv3 4.0 - CVE-2025-58436
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
mediumCVSSv3 5.1 - CVE-2025-58364
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
mediumCVSSv3 6.5 - CVE-2025-58060
OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme.
highCVSSv3 8.0 - CVE-2025-57812
CUPS ist ein standardsbasiertes, quelloffenes Drucksystem, und `libcupsfilters` enthält den Code der Filter des ehemaligen Pakets `cups-f…
lowCVSSv3 3.7