Source: cups Version: 2.4.18-1 X-Debbugs-CC: [email protected] Severity: important Tags: security upstream
Hi, The following vulnerability was published for cups. CVE-2026-107890[0]: | OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference | caused by repeated IPP group tags in job-creation requests. IPP | parsing creates unnamed separator attributes with IPP_TAG_ZERO, but | add_job() converts these separators to IPP_TAG_JOB. During job | startup, get_options()/ipp_length() subsequently calls strlen() on a | NULL attribute name, terminating cupsd and disrupting all queues. A | single crafted Print-Job request can trigger the crash when the | client can reach the scheduler and submit jobs to an accepting, | enabled queue supporting the submitted document format. Anonymous | submission is possible when permitted by listener and access-control | configuration. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-107890 https://www.cve.org/CVERecord?id=CVE-2026-107890 [1] https://github.com/OpenPrinting/cups/security/advisories/GHSA-wjc4-qhjr-5m5x [2] https://github.com/OpenPrinting/cups/commit/f3fb41912e4e29dbbbe7c4afd4fe48508af21bc0 Please adjust the affected versions in the BTS as needed. Regards, Salvatore
