Source: cups
Version: 2.4.18-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for cups.

CVE-2026-87875[0]:
| The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a
| source-length bound and can read past the end of the source buffer,
| resulting in a heap out-of-bounds read. This is reachable via SNMP
| supply-description parsing in backend/snmp-supplies.c with attacker-
| controlled content.


CVE-2026-87876[1]:
| Two case-insensitive comparisons on request-derived usernames
| outside the main authorization path in CUPS's scheduler (printer ACL
| validation and private-attribute filtering) could allow bypass of
| username-based access controls in certain configurations.

The security tracker references list as well the GHSAs for those
issues.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-87875
    https://www.cve.org/CVERecord?id=CVE-2026-87875
[1] https://security-tracker.debian.org/tracker/CVE-2026-87876
    https://www.cve.org/CVERecord?id=CVE-2026-87876

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to