Impact
OpenPrinting CUPS before 2.4.20 contains a double‑free bug in printer‑class management. When a class is updated, the add_class() routine frees the pointer to the previous printer list without clearing it. If the new list fails validation, the old printer pointer remains dangling. A subsequent delete operation drops the same pointer again, causing memory corruption and scheduler crash. The primary impact is a scheduler‑wide denial of service rather than privilege escalation or data exfiltration. The weakness is a classic double‑free vulnerability (CWE‑415).
Affected Systems
Affected systems are all installations of OpenPrinting CUPS prior to version 2.4.20. The CUPS package name is openprinting:cups, and the vulnerability applies to any configuration that allows class modification or deletion. No specific platform or architecture is limited; any system running the vulnerable CUPS package is in scope. Unsupported or patched versions are assumed safe.
Risk and Exploitability
The CVSS score is 2.3, indicating low severity. EPSS data is not available, and the flaw is not listed in CISA KEV. Exploitation requires an authorized client with the ability to modify or delete printer classes, which the default policy grants to @SYSTEM. Therefore the likely attack vector is an authenticated privileged client, either local or remote if proper authentication is obtained. The risk to a system is a denial-of-service that can be triggered by a single action from an authorized user; no remote unauthenticated access is needed, and no privileged escalation occurs beyond the allowed permissions.
OpenCVE Enrichment