Hi,
I am reporting an unresolved CVE affecting the cups source package
(specifically libcups2t64) on Debian Trixie (Debian 13), identified
via a Prisma scanner.
* CVE-2026-34980 (High)
please update your Prisma scanner or use a software that is not broken.
According to [1] the CVSS Version 4.0 score of this CVE is 6.1, which is
"just" medium. This score was evaluated by upstream and should be the
most correct one.
Notes:
While this vulnerability strictly requires the network-exposed cupsd
daemon (which we have removed), the library binary libcups2t64 remains
flagged by container image scanners. This client library is required
as a dependency for chromium and cannot be removed.
Thanks for this note, which makes things more clear. As the CVE is only
related to the job scheduler, which is only used in the server, the
library is not affected at all by this CVE. So it is really your scanner
that is broken. In order to minimize such false positives, I suggest to
use some working software.
This issue is fixed upstream in cups v2.4.17. Could you please advise
on when a patched version will be introduced to Trixie?
This question causes some astonishment on my side. Is there anything you
have done to support Debian lately? Maybe I looked at the wrong places,
but I found nothing. Do you really expect an answer other than "It is
done when it is done."?
Thorsten
[1] https://nvd.nist.gov/vuln/detail/cve-2026-34980