On Thu, Sep 10, 2026 at 03:16:50AM +0000, Samonte, Joshua wrote:
> Package: cups
> Version: 2.4.10-3+deb13u2
> Severity: grave
> Tags: security
> 
> Hi Team,
> 
> I am reporting an unresolved CVE affecting the cups source package
> (specifically libcups2t64) on Debian Trixie (Debian 13), identified
> via a Prisma scanner.
> 
> 
>   *   CVE-2026-34980 (High)
> 
> Notes:
> While this vulnerability strictly requires the network-exposed cupsd
> daemon (which we have removed), the library binary libcups2t64
> remains flagged by container image scanners. This client library is
> required as a dependency for chromium and cannot be removed.
> 
> This issue is fixed upstream in cups v2.4.17. Could you please
> advise on when a patched version will be introduced to Trixie?

People at Accenture, stop wasting our time. Please read
https://www.debian.org/security/faq#cve-severity-assessment

Regards,
Salvatore

Reply via email to