On Thu, Sep 10, 2026 at 03:16:50AM +0000, Samonte, Joshua wrote: > Package: cups > Version: 2.4.10-3+deb13u2 > Severity: grave > Tags: security > > Hi Team, > > I am reporting an unresolved CVE affecting the cups source package > (specifically libcups2t64) on Debian Trixie (Debian 13), identified > via a Prisma scanner. > > > * CVE-2026-34980 (High) > > Notes: > While this vulnerability strictly requires the network-exposed cupsd > daemon (which we have removed), the library binary libcups2t64 > remains flagged by container image scanners. This client library is > required as a dependency for chromium and cannot be removed. > > This issue is fixed upstream in cups v2.4.17. Could you please > advise on when a patched version will be introduced to Trixie?
People at Accenture, stop wasting our time. Please read https://www.debian.org/security/faq#cve-severity-assessment Regards, Salvatore

