CVE-2026-64612
Security update for cups-filters
Beschreibung
Ein Fehler wurde in libcupsfilters und cups-filters gefunden. Die Funktion zum Lesen von PNG-Bildern erstellt einen libpng-Leser ohne die Installation eines Fehlerrückgabehandlers, wodurch der CUPS-Bildfilterprozess abbricht, wenn ein fehlerhaftes PNG-Datei verarbeitet wird. Ein unauthentisierter Angreifer könnte dies ausnutzen, indem er einen speziell erstellten PNG-Druckauftrag einreicht, was zu einem Denial-of-Service-Angriff auf den laufenden Druckauftrag führt.
Metriken
Weakness-Klassen (CWE)
CWE-248Base
Uncaught Exception
An exception is thrown from a function, but it is not caught.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- CVE Modified2026-08-24 10:16 UTC· secalert@redhat.com
- Reference: https://access.redhat.com/errata/RHSA-2026:58560
- Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 10 (+2) → Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9 (+2)
- CVE Modified2026-08-19 14:17 UTC· secalert@redhat.com
- Reference: https://access.redhat.com/errata/RHSA-2026:56965
- Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7 (+2) → Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7 (+2)
- CVE Modified2026-07-20 19:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-64612","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
- New CVE Received2026-07-20 18:16 UTC· secalert@redhat.com
- Affected: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7 (+2)
- Description: A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.
- CVSS V3.1: AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- CWE: CWE-248
Betroffene Produkte
Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.
Red Hat
Enterprise Linux9
Quellen & Referenzen
- https://access.redhat.com/security/cve/CVE-2026-64611vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2502799issue-trackingx_refsource_REDHAT
- https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-rcq7-rv5g-j3r4
- https://access.redhat.com/errata/RHSA-2026:56965vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/security/cve/CVE-2026-64612vdb-entryx_refsource_REDHAT
- https://bugzilla.redhat.com/show_bug.cgi?id=2502801issue-trackingx_refsource_REDHAT
- https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch
- https://access.redhat.com/errata/RHSA-2026:57451vendor-advisoryx_refsource_REDHAT
- https://access.redhat.com/errata/RHSA-2026:58560vendor-advisoryx_refsource_REDHAT