Hi,

I am reporting an unresolved CVE affecting the cups source package (specifically libcups2t64) on Debian Trixie (Debian 13), identified via a Prisma scanner.

  * CVE-2026-34980 (High)


please update your Prisma scanner or use a software that is not broken.
According to [1] the CVSS Version 4.0 score of this CVE is 6.1, which is "just" medium. This score was evaluated by upstream and should be the most correct one.

Notes:

While this vulnerability strictly requires the network-exposed cupsd daemon (which we have removed), the library binary libcups2t64 remains flagged by container image scanners. This client library is required as a dependency for chromium and cannot be removed.


Thanks for this note, which makes things more clear. As the CVE is only related to the job scheduler, which is only used in the server, the library is not affected at all by this CVE. So it is really your scanner that is broken. In order to minimize such false positives, I suggest to use some working software.

This issue is fixed upstream in cups v2.4.17. Could you please advise on when a patched version will be introduced to Trixie?


This question causes some astonishment on my side. Is there anything you have done to support Debian lately? Maybe I looked at the wrong places, but I found nothing. Do you really expect an answer other than "It is done when it is done."?

  Thorsten


[1] https://nvd.nist.gov/vuln/detail/cve-2026-34980

Reply via email to