Impact
OpenPrinting CUPS versions up to 2.4.20 contain a resource‑exhaustion flaw in the scheduler’s timeout logic for pending print jobs. During a client’s in‑flight Send‑Document operation the scheduler incorrectly suppresses timeout processing for all other pending jobs, regardless of which connection owns those jobs. An attacker can therefore keep an incomplete HTTP request open, preventing unrelated jobs from expiring. If Create‑Job is permitted, the number of incomplete jobs can grow until the MaxJobs limit is reached, after which new legitimate print submissions are rejected. The weakness is classified as CWE‑770 and results in a denial of service that can disable the print service for legitimate users.
Affected Systems
The vulnerability affects installations of OpenPrinting CUPS version 2.4.20 and earlier. Any system that exposes the IPP service and allows clients to submit incomplete print jobs is potentially impacted. Upgrading to a version newer than 2.4.20 eliminates the flaw.
Risk and Exploitability
The CVSS score of 3.3 indicates low severity, and the EPSS score is not available while the issue is not listed in CISA KEV. Exploitation requires network access to the IPP service and the ability to send an incomplete Send‑Document operation. Once exploited, the scheduler will suppress timeouts for unrelated jobs, enabling the queue to reach its MaxJobs limit and causing legitimate jobs to be rejected. Because the flaw can be triggered remotely and has persistence until the held connection closes, the risk is moderate for environments with open IPP access, but the availability impact warrants timely attention.
OpenCVE Enrichment