Source: cups Version: 2.4.18-1 X-Debbugs-CC: [email protected] Severity: important Tags: security upstream
Hi, The following vulnerability was published for cups. CVE-2026-107655[0]: | A flaw was found in CUPS. When processing embedded job ticket | comments within documents, the service improperly handles specific | IPP attributes, causing an unhandled null pointer dereference. An | unauthenticated attacker permitted to submit jobs to a shared | printer queue can send a crafted Internet Printing Protocol (IPP) | request to crash the print daemon, resulting in a temporary Denial | of Service (DoS) for all printing services. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-107655 https://www.cve.org/CVERecord?id=CVE-2026-107655 [1] https://github.com/OpenPrinting/cups/security/advisories/GHSA-58wv-9ffm-5w78 [2] https://github.com/OpenPrinting/cups/commit/25d68309b1af89c4b003f27f56ab0f8e7a189ea3 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
