CVE-2026-34979

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Beschreibung

OpenPrinting CUPS ist ein quelloffenes Drucksystem für Linux und andere Unix-ähnliche Betriebssysteme. In Versionen 2.4.16 und früher gibt es einen heap-basierten Pufferüberlauf im CUPS-Scheduler beim Erstellen von Filteroptionstrings aus Jobattributen. Zum Zeitpunkt der Veröffentlichung sind keine öffentlichen Patches verfügbar.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
5.3
Quelle: nvd-v3
31.3 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.4 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-04-17 17:04 UTC
CWE-122

Weakness-Klassen (CWE)

  • CWE-122Variant

    Heap-based Buffer Overflow

    A heap overflow condition is a buffer overflow, where the buffer that can be overwritten is allocated in the heap portion of memory, generally meaning that the buffer was allocated using a routine such as malloc().

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Translated2026-07-24 21:10 UTC· nvd@nist.gov
    • Translation: Title: cups de OpenPrinting, Description: OpenPrinting CUPS es un sistema de impresión de código abierto para Linux y otros sistemas operativos tipo Unix. En las versiones 2.4.16 y anteriores, existe un desbordamiento de búfer basado en montículo en el planificador de CUPS al construir cadenas de opciones de filtro a partir del atributo de trabajo. Al momento de la publicación, no hay parches disponibles públicamente.

Betroffene Betriebssysteme

  • linux

    ubuntu / cupsjammy

  • linux

    ubuntu / cupsnoble

  • linux

    ubuntu / cupsquesting

  • linux

    ubuntu / cupsresolute

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • Open Source

    CUPS< 2.4.15

    gefixt in 2.4.15

  • openprinting

    cups2.4.13

  • openprinting

    cups2.4.16

  • openprinting

    cups-filters1.28.17

  • openprinting

    cups-filters1.28.18

  • openprinting

    libcupsfilters2.0.0 – 2.1.1

  • openprinting

    libcupsfilters2.0.0 – 2.1.2

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-34979