Description
OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdCheckJobs(). The scheduler suppresses timeout processing for all pending jobs whenever any client connection has an in-flight Send-Document operation, without matching that connection to the job being examined. A client allowed to reach the IPP service can hold an incomplete HTTP request containing parsed Send-Document headers before operation authorization, preventing unrelated incomplete jobs from expiring. Where Create-Job submission is allowed, incomplete jobs can accumulate until MaxJobs is exhausted and further legitimate print submissions are rejected. The suppression ends when the held connection closes.
Published: 2026-10-09
Score: 3.3 Low
EPSS: n/a
KEV: No
Impact: Denial of Service via Resource Exhaustion
Action: Patch Now
AI Analysis

Impact

OpenPrinting CUPS versions up to 2.4.20 contain a resource‑exhaustion flaw in the scheduler’s timeout logic for pending print jobs. During a client’s in‑flight Send‑Document operation the scheduler incorrectly suppresses timeout processing for all other pending jobs, regardless of which connection owns those jobs. An attacker can therefore keep an incomplete HTTP request open, preventing unrelated jobs from expiring. If Create‑Job is permitted, the number of incomplete jobs can grow until the MaxJobs limit is reached, after which new legitimate print submissions are rejected. The weakness is classified as CWE‑770 and results in a denial of service that can disable the print service for legitimate users.

Affected Systems

The vulnerability affects installations of OpenPrinting CUPS version 2.4.20 and earlier. Any system that exposes the IPP service and allows clients to submit incomplete print jobs is potentially impacted. Upgrading to a version newer than 2.4.20 eliminates the flaw.

Risk and Exploitability

The CVSS score of 3.3 indicates low severity, and the EPSS score is not available while the issue is not listed in CISA KEV. Exploitation requires network access to the IPP service and the ability to send an incomplete Send‑Document operation. Once exploited, the scheduler will suppress timeouts for unrelated jobs, enabling the queue to reach its MaxJobs limit and causing legitimate jobs to be rejected. Because the flaw can be triggered remotely and has persistence until the held connection closes, the risk is moderate for environments with open IPP access, but the availability impact warrants timely attention.

Generated by OpenCVE AI on October 9, 2026 at 05:51 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenPrinting CUPS to a version newer than 2.4.20 when available
  • If an upgrade cannot be performed immediately, restrict IPP access to authenticated clients and consider reducing the MaxJobs limit to limit job accumulation
  • Actively monitor the print queue for stalled or incomplete jobs and clear them manually while the vulnerability remains open

Generated by OpenCVE AI on October 9, 2026 at 05:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Title CUPS Scheduler Timeout Suppression Enables Resource Exhaustion

Fri, 09 Oct 2026 04:15:00 +0000

Type Values Removed Values Added
Description OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdCheckJobs(). The scheduler suppresses timeout processing for all pending jobs whenever any client connection has an in-flight Send-Document operation, without matching that connection to the job being examined. A client allowed to reach the IPP service can hold an incomplete HTTP request containing parsed Send-Document headers before operation authorization, preventing unrelated incomplete jobs from expiring. Where Create-Job submission is allowed, incomplete jobs can accumulate until MaxJobs is exhausted and further legitimate print submissions are rejected. The suppression ends when the held connection closes.
First Time appeared Openprinting
Openprinting cups
Weaknesses CWE-770
CPEs cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*
Vendors & Products Openprinting
Openprinting cups
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Openprinting Cups
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-09T03:54:16.283Z

Reserved: 2026-10-09T03:54:15.382Z

Link: CVE-2026-107885

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T04:18:04.940

Modified: 2026-10-09T04:18:04.940

Link: CVE-2026-107885

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T07:00:10Z

Weaknesses
  • CWE-770

    Allocation of Resources Without Limits or Throttling