Opened 3 hours ago

Closed 52 minutes ago

#24070 closed enhancement (fixed)

cups-2.4.20

Reported by: Joe Locash Owned by: SecurityAdvisory
Priority: elevated Milestone: 98-Security
Component: BOOK Version: git
Severity: medium Keywords:
Cc:

Description

v2.4.20 - 2026-10-05
--------------------

- SECURITY-5.7: The scheduler did not open temporary PPD files in exclusive
  mode (CVE-2026-55480)
- SECURITY-5.5: The scheduler did not remove all job status attributes from a
  job creation request (GHSA-7j85-5r23-xhvh)
- SECURITY-5.3: The scheduler did not validate the request language value
  (CVE-2026-61702)
- SECURITY-4.6: Attribute names were not validated as proper keyword values
  (GHSA-w9hj-hq9p-m7f6)
- SECURITY-4.3: The `cupsUTF32toUTF8` function incorrectly treated UTF-32
  values as 64-bit (CVE-2026-87875)
- SECURITY-4.1: Held jobs for temporary print queues could crash the scheduler
  (GHSA-qqm8-4q5h-jg55)
- SECURITY-3.3: The backend did not sanitize IPP attribute strings
  (CVE-2026-55453)
- SECURITY-3.3: The scheduler did not filter out group separators from job
  submissions (GHSA-wjc4-qhjr-5m5x)
- SECURITY-3.0: Quota and policy operations did not treat usernames as case-
  sensitive (CVE-2026-87876)
- SECURITY-3.0: The scheduler's startup permission checks were vulnerable to
  TOU attacks (GHSA-gj33-wxpv-6fgg)
- SECURITY-2.5: The scheduler did not sanitize fax numbers (CVE-2026-55467)
- SECURITY-2.5: The 'mailto' notifier did not sanitize the recipient address
  provided to the sendmail command (CVE-2026-105326)
- SECURITY-2.3: The scheduler could crash when modifying a class
  (GHSA-pwg4-pv39-8c22)
- Increased the size of the SNMP supply name buffer used by the network backends
  (Issue #1604)
- The USB backend now clears a halt on USB errors (Issue #1606)
- Updated a few character tests for signed char platforms (Issue #1623)
- Updated dateTime parsing in IPP files (Issue #1710)
- Now explicitly limit IPP attribute names to 255 bytes (Issue #1694)
- Added validation of IPP "printer-state-reasons" and
  "printer-mandatory-job-attributes" attributes (Issue #1632)
- Added missing Set-Printer-Attributes policy to cupsd.conf.
- Removed problematic debug printfs from `dnssd` backend.
- Fixed mapping of standard PPD/PWG/legacy media size names to the local PPD
  size name (Issue #1375)
- Fixed handling of multiple PPD: keywords from filters (Issue #1562,
  related to CVE-2026-34980)
- Fixed handling of Kerberos user@REALM identities for user validation and
  quotas when StripUserDomain is not enabled (Issue #1584)
- Fixed raster error reporting overflow (Issue #1607)
- Fixed `cupsRasterInterpretPPD` handling of bad numbers (Issue #1608)
- Fixed SNMP hex string debug output (Issue #1610)
- Fixed some web interface bugs (Issue #1611)
- Fixed some compression issues in the rastertoepson and rastertohp drivers
  (Issue #1613)
- Fixed MIME `char` rule handling (Issue #1614)
- Fixed duplicate local printers (Issue #1531, Issue #1586, Issue #1593,
  Issue #1620)
- Fixed PPD cache memory leak (Issue #1629, Issue #1344)
- Fixed escaping of spaces in option values (Issue #1630)
- Fixed potential buffer overflow in `cupsCopyDestConflicts` (Issue #1631)
- Fixed backchannel parsing bug in `commandtops` filter (Issue #1637)
- Fixed section parsing in the web help indexing code (Issue #1641)
- Fixed potential buffer overrun in rastertolabel filter (Issue #1644)
- Fixed potential buffer overrun in rastertohp filter (Issue #1650)
- Fixed media selection with a mix of PPD and IPP options (Issue #1651)
- Fixed potential access of deleted IPP Everywhere printer (Issue #1655)
- Fixed limiting of PPD custom number output for large numbers (Issue #1656)
- Fixed a potential output length bug in the rastertohp driver (Issue #1658)
- Fixed a potential buffer underflow buf in the `ippAdd/SetStringf(v)` functions
  (Issue #1664)
- Fixed handling of TLS system priorities (Issue #1677)
- Fixed D-Bus notification policy definition (Issue #1691)
- Fixed raster fallback for IPP Everywhere printers (Issue #1703)
- Fixed potential SNMP OID side-channel overflow (Issue #1719)
- Fixed potential scheduler printer use-after-free bug (Issue #1722)
- Fixed several issues reported by Coverity
- Fixed case-sensitive PPD keyword comparisons when filtering keyword updates
  from filters.
- Fixed potential buffer overrun in `cupsDoAuthentication`.

Change History (2)

comment:1 by Joe Locash, 2 hours ago

Milestone: 13.2 → 98-Security
Owner: changed from Joe Locash to SecurityAdvisory
Status: assigned → new

Fixed at ef5e3a3b47. Leaving open for SA.

comment:2 by Bruce Dubbs, 52 minutes ago

Resolution: → fixed
Status: new → closed

Advisory sa-13.1-055 has been issued.

Note: See TracTickets for help on using tickets.