Opened 3 hours ago
Closed 52 minutes ago
#24070 closed enhancement (fixed)
cups-2.4.20
| Reported by: | Joe Locash | Owned by: | SecurityAdvisory |
|---|---|---|---|
| Priority: | elevated | Milestone: | 98-Security |
| Component: | BOOK | Version: | git |
| Severity: | medium | Keywords: | |
| Cc: |
Description
v2.4.20 - 2026-10-05 -------------------- - SECURITY-5.7: The scheduler did not open temporary PPD files in exclusive mode (CVE-2026-55480) - SECURITY-5.5: The scheduler did not remove all job status attributes from a job creation request (GHSA-7j85-5r23-xhvh) - SECURITY-5.3: The scheduler did not validate the request language value (CVE-2026-61702) - SECURITY-4.6: Attribute names were not validated as proper keyword values (GHSA-w9hj-hq9p-m7f6) - SECURITY-4.3: The `cupsUTF32toUTF8` function incorrectly treated UTF-32 values as 64-bit (CVE-2026-87875) - SECURITY-4.1: Held jobs for temporary print queues could crash the scheduler (GHSA-qqm8-4q5h-jg55) - SECURITY-3.3: The backend did not sanitize IPP attribute strings (CVE-2026-55453) - SECURITY-3.3: The scheduler did not filter out group separators from job submissions (GHSA-wjc4-qhjr-5m5x) - SECURITY-3.0: Quota and policy operations did not treat usernames as case- sensitive (CVE-2026-87876) - SECURITY-3.0: The scheduler's startup permission checks were vulnerable to TOU attacks (GHSA-gj33-wxpv-6fgg) - SECURITY-2.5: The scheduler did not sanitize fax numbers (CVE-2026-55467) - SECURITY-2.5: The 'mailto' notifier did not sanitize the recipient address provided to the sendmail command (CVE-2026-105326) - SECURITY-2.3: The scheduler could crash when modifying a class (GHSA-pwg4-pv39-8c22) - Increased the size of the SNMP supply name buffer used by the network backends (Issue #1604) - The USB backend now clears a halt on USB errors (Issue #1606) - Updated a few character tests for signed char platforms (Issue #1623) - Updated dateTime parsing in IPP files (Issue #1710) - Now explicitly limit IPP attribute names to 255 bytes (Issue #1694) - Added validation of IPP "printer-state-reasons" and "printer-mandatory-job-attributes" attributes (Issue #1632) - Added missing Set-Printer-Attributes policy to cupsd.conf. - Removed problematic debug printfs from `dnssd` backend. - Fixed mapping of standard PPD/PWG/legacy media size names to the local PPD size name (Issue #1375) - Fixed handling of multiple PPD: keywords from filters (Issue #1562, related to CVE-2026-34980) - Fixed handling of Kerberos user@REALM identities for user validation and quotas when StripUserDomain is not enabled (Issue #1584) - Fixed raster error reporting overflow (Issue #1607) - Fixed `cupsRasterInterpretPPD` handling of bad numbers (Issue #1608) - Fixed SNMP hex string debug output (Issue #1610) - Fixed some web interface bugs (Issue #1611) - Fixed some compression issues in the rastertoepson and rastertohp drivers (Issue #1613) - Fixed MIME `char` rule handling (Issue #1614) - Fixed duplicate local printers (Issue #1531, Issue #1586, Issue #1593, Issue #1620) - Fixed PPD cache memory leak (Issue #1629, Issue #1344) - Fixed escaping of spaces in option values (Issue #1630) - Fixed potential buffer overflow in `cupsCopyDestConflicts` (Issue #1631) - Fixed backchannel parsing bug in `commandtops` filter (Issue #1637) - Fixed section parsing in the web help indexing code (Issue #1641) - Fixed potential buffer overrun in rastertolabel filter (Issue #1644) - Fixed potential buffer overrun in rastertohp filter (Issue #1650) - Fixed media selection with a mix of PPD and IPP options (Issue #1651) - Fixed potential access of deleted IPP Everywhere printer (Issue #1655) - Fixed limiting of PPD custom number output for large numbers (Issue #1656) - Fixed a potential output length bug in the rastertohp driver (Issue #1658) - Fixed a potential buffer underflow buf in the `ippAdd/SetStringf(v)` functions (Issue #1664) - Fixed handling of TLS system priorities (Issue #1677) - Fixed D-Bus notification policy definition (Issue #1691) - Fixed raster fallback for IPP Everywhere printers (Issue #1703) - Fixed potential SNMP OID side-channel overflow (Issue #1719) - Fixed potential scheduler printer use-after-free bug (Issue #1722) - Fixed several issues reported by Coverity - Fixed case-sensitive PPD keyword comparisons when filtering keyword updates from filters. - Fixed potential buffer overrun in `cupsDoAuthentication`.
Change History (2)
comment:1 by , 2 hours ago
| Milestone: | 13.2 → 98-Security |
|---|---|
| Owner: | changed from to |
| Status: | assigned → new |
comment:2 by , 52 minutes ago
| Resolution: | → fixed |
|---|---|
| Status: | new → closed |
Advisory sa-13.1-055 has been issued.
Note:
See TracTickets
for help on using tickets.

Fixed at ef5e3a3b47. Leaving open for SA.