Opened 8 weeks ago

Closed 6 weeks ago

#23707 closed enhancement (fixed)

libcupsfilters-2.2.0 (Security Update)

Reported by: Bruce Dubbs Owned by: SecurityAdvisory
Priority: normal Milestone: 98-Security
Component: BOOK Version: git
Severity: normal Keywords:
Cc:

Description

New minor version.

Change History (5)

comment:1 by Bruce Dubbs, 7 weeks ago

Owner: changed from blfs-book to Bruce Dubbs
Status: new → assigned

comment:2 by Bruce Dubbs, 7 weeks ago

Summary: libcupsfilters-2.2.0 → libcupsfilters-2.2.0 (Security Update)

CHANGES IN V2.2.0 (6th August 2026)

  • Eliminated the use of C++ in libcupsfilters, to get all regular C
    • Replaced QPDF by PDFio as PDF manipulation library in libcupsfilters. Modified the filter functions cfFilterPDFToPDF(), cfFilterPCLmToRaster(), cfFilterPWGToPDF(), cfFilterBannerToPDF(). Also turned the code from C++ into C.
    • In cfFilterPDFToRaster() replaced use of libpoppler by using PDFio and also the external executable pdftoppm of poppler-utils, Also here turned C++ code into C.
    • Made sure that the API/ABI of libcupsfilters did not change
    • Also added extra CI tests via cupsfilters/test-filter-cases.txt.
    • PDFio 1.6.4 now required for building libcupsfilters. Older versions have bugs.
    • GSoC 2024 project of Uddhav Phatak: ​https://medium.com/@uddhavphatak/gsoc-2024-final-report-the-refactor-report-a46756e9d6ce

  • Non-Latin language input support for cfFilterTextToPDF()
    • Removed FC_MONO constraint to allow proportional fonts. Some languages have non-monospaced scripts and now they can correctly load their intended fonts.
    • Default to UTF-8 when charset metadata is missing. cfFilterTextToPDF() expects UTF-8 input by default now.
    • Add Devanagari Unicode range to utf-8 charsets

  • Added JPEG‑XL Support to libcupsfilters. Now jobs in the high-quality JPEG-XL image format can be sent directly to CUPS and cfFilterImageTo...() filter functions read and convert these files.

  • Print quality improvements
    • In cfFilterGhostscript() introduced cupsHalftoneType dithering algorithms. Controlled with halftone-type job option or cupsHalftoneType PPD option. Added stochastic halftoning, bi-level threshold, and an algorithm from foo2zjs, 8x8, genordered, and spot from PDF
    • Added user-settable gamma parameter and remove Ghostscript's default one.
    • Fixed 1-bit mono dithering of 100% black pixel. Prevents white holes in the text
  • CI: Implemented complete GitHub Actions pipeline (Build, Unit tests, CodeQL, Cppcheck)
    • GitHub workflow for CI added
    • Static analysis (CodeQL, Cppcheck)
    • Build and unit tests multiple architecture (x86 64-bit, ARM 64- and 32-bit, and RISC-V 64-bit) and for different CUPS versions (2.4.x, 2.5.x, 3.x). Tests on 12 combos
    • Emulations used for ARM 32-bit and RISC-V
    • Use make check and also Debian's autopkgtests as unit tests
    • Workflows optimized with caching and parallel jobs
    • Fixed several issues disovered with the added static analysis
  • CI: Improvements of unit tests
    • Add malformed PDF testcase for pdftopdf validation
    • Added UTF-8 non-Latin regression coverage for Cyrillic, Greek, Arabic
    • Let testfilters just go through all lines of test cases instead of using line count as a parameter
    • Add optional manual FilterChain() support to testfilters. Manually providing a filter chain is optional, if not supplied, it is set automatically as before
    • Added a deterministic build-time multipage UTF-8 lorem generator

  • Fixed (crasher) bugs found in security audit by 7ASecurity
    • Crash from wrong tag *-supported/*-default attributes, in the cfIPPAttrEnumValForPrinter() function. Check IPP tags (data types) to avoid NULL derefences
    • Crash from wrong-tag driverless IPP attributes. cfGetBackSideOrientation() and cfGetPrintRenderIntent() look up several IPP attributes. Also here check tags/data types to avoid NULL derefences
  • SECURITY: Out-of-bounds write in cfFilterPDFToRaster() if PDF has too large page dimensions. Crop dimensions to maximum allowed by standard, 14400x14400pt, 200x200in, 5x5m, if needed. (CVE-2025-64503) Moderate
  • SECURITY: Vulnerabilities by image input with wrong color space/depth/bits-per-pixel combo.
    • Fix heap-buffer overflow write in cfImageLut
    • Reject color images with 1 bit per sample
    • Reject images where the number of samples does not correspond with the color space
    • Reject images with planar color configuration
    • Reject images with vertical scanlines (CVE-2025-57812)
  • SECURITY: cfFilterImageTo...(): Added error handling for libpng and libjpeg function calls to avoid the process being aborted. (CVE-2026-64612)
  • SECURITY: Fix possible infinite loop when parsing device IDs, also avoid empty device IDs (CVE-2026-64611)
  • Fixed heap buffer overflow in bilinear zoom of images
  • Out-of-bounds read in NormalizeMakeModel when manufacturer name too long
  • Use ColorModel or output-mode if there's no print-color-mode
  • Fix cache thrashing for large images when cropping them
  • Fix for potential heap-buffer-overflow when reading TIFF images with more than one sample per pixel
  • Unified return value of TIFF related functions to -1
  • When zooming images check whether X and Y size dimensions are not zero
  • pdftoraster, gsto..., mupdftopwg: Fix NULL-pointer dereference when parsing %%PDFTOPDF... comments
  • pdftoraster: Check result of render_page() as it may return NULL if the page is not properly constructed
  • imagetopdf: convert custom media size min_width and min_height to points
  • cfFilterChain(): Initialize return value to 0. In some cases the function exits with non-zero status when all filters exit with no errors (zero status).
  • Fixed Deadlock in filter chain When one filter fails
  • cfFilterTextToPDF(): Let all Arabic characters be rendered right-to-left
  • Fix build with libcups3
    • Add additional changed function cupsParseOptions()
    • Only define struct cups_media_s if running a version older then CUPS 2.5.x
    • Update testfilters.c to use CUPS 3.0 API with compatibility shim for CUPS 2.x and older. Given that this is an end-user program, we don't want to include libcups2-private.h. Also tweaked Makefile to link against proper CUPS library.
    • Removed unused reference to cups/backend.h.
  • Allow building without fontconfig. Controllable by ./configure option. When building without fontconfig, cfFilterTextToPDF() gets no-op (to keep API)
  • Build-time option for alternative CJK font name. ./configure option -with-cjk-fonts sets alternative name
  • Fix missing sys/stat.h include for Solaris
  • Use /bin/sh for testfilters.sh to avoid dependency on bash
  • cfFilterImageToPDF(): Added extra debug log messages concerning page orientation
Last edited 7 weeks ago by Bruce Dubbs (previous) (diff)

comment:3 by Bruce Dubbs, 7 weeks ago

It looks like we can remove qpdf and will need to replace it with pdfio.

​https://github.com/michaelrsweet/pdfio/releases/download/v1.6.4/pdfio-1.6.4.tar.gz

  ./configure --prefix=/usr    \
              --disable-static \
              --enable-shared  
  make
  make install

libpng is optional but should probably be recommended.

docdir is not honored. Need to 'mv /usr/share/doc/pdfio /usr/share/doc/pdfio-1.6.4' manually.

comment:4 by Bruce Dubbs, 7 weeks ago

Milestone: 13.1 → 98-Security
Owner: changed from Bruce Dubbs to SecurityAdvisory
Status: assigned → new

comment:5 by Bruce Dubbs, 6 weeks ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.0-197 has been issued.

Note: See TracTickets for help on using tickets.