==========================================================================
Ubuntu Security Notice USN-8578-1
July 21, 2026

CUPS vulnerability
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 16.04 LTS

Summary:

CUPS could be made to run programs as the lp user if it received specially 
crafted print job requests.

Software Description:
- cups: Common UNIX Printing System(tm)

Details:

It was discovered that CUPS did not properly filter control characters in IPP 
string attributes and PPD keywords. An unauthenticated attacker could exploit 
this to execute arbitrary code as the lp user on systems with shared target 
queues.

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
  cups                            2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro
  cups-bsd                        2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro
  cups-client                     2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro
  cups-common                     2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro
  cups-core-drivers               2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro
  cups-daemon                     2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro
  libcups2                        2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-8578-1
  CVE-2026-34980

Attachment: signature.asc
Description: OpenPGP digital signature

Reply via email to