Description
OpenPrinting CUPS before 2.4.20 contains a double-free in printer-class management. When CUPS-Add-Modify-Class replaces an existing class member list, add_class() frees pclass->printers without clearing the pointer. If subsequent validation fails, the class retains the dangling pointer; CUPS-Delete-Class subsequently frees the same allocation in cupsdDeletePrinter(). A client authorized to modify and delete classes can cause scheduler-wide denial of service. The default policy requires @SYSTEM privileges.
Published: 2026-10-09
Score: 2.3 Low
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

OpenPrinting CUPS before 2.4.20 contains a double‑free bug in printer‑class management. When a class is updated, the add_class() routine frees the pointer to the previous printer list without clearing it. If the new list fails validation, the old printer pointer remains dangling. A subsequent delete operation drops the same pointer again, causing memory corruption and scheduler crash. The primary impact is a scheduler‑wide denial of service rather than privilege escalation or data exfiltration. The weakness is a classic double‑free vulnerability (CWE‑415).

Affected Systems

Affected systems are all installations of OpenPrinting CUPS prior to version 2.4.20. The CUPS package name is openprinting:cups, and the vulnerability applies to any configuration that allows class modification or deletion. No specific platform or architecture is limited; any system running the vulnerable CUPS package is in scope. Unsupported or patched versions are assumed safe.

Risk and Exploitability

The CVSS score is 2.3, indicating low severity. EPSS data is not available, and the flaw is not listed in CISA KEV. Exploitation requires an authorized client with the ability to modify or delete printer classes, which the default policy grants to @SYSTEM. Therefore the likely attack vector is an authenticated privileged client, either local or remote if proper authentication is obtained. The risk to a system is a denial-of-service that can be triggered by a single action from an authorized user; no remote unauthenticated access is needed, and no privileged escalation occurs beyond the allowed permissions.

Generated by OpenCVE AI on October 9, 2026 at 05:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to CUPS 2.4.20 or later.
  • If upgrade is not possible, restrict printer class modification and deletion to trusted users by adjusting the CUPS policy files to remove @SYSTEM and enforce stronger permissions.
  • Restart the cups daemon after policy changes and monitor for unexpected crashes.

Generated by OpenCVE AI on October 9, 2026 at 05:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Title Double‑Free Vulnerability in CUPS Printer‑Class Management Leads to Denial of Service

Fri, 09 Oct 2026 04:15:00 +0000

Type Values Removed Values Added
Description OpenPrinting CUPS before 2.4.20 contains a double-free in printer-class management. When CUPS-Add-Modify-Class replaces an existing class member list, add_class() frees pclass->printers without clearing the pointer. If subsequent validation fails, the class retains the dangling pointer; CUPS-Delete-Class subsequently frees the same allocation in cupsdDeletePrinter(). A client authorized to modify and delete classes can cause scheduler-wide denial of service. The default policy requires @SYSTEM privileges.
First Time appeared Openprinting
Openprinting cups
Weaknesses CWE-415
CPEs cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*
Vendors & Products Openprinting
Openprinting cups
References
Metrics cvssV3_1

{'score': 2.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Openprinting Cups
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-09T04:00:29.308Z

Reserved: 2026-10-09T04:00:28.517Z

Link: CVE-2026-107886

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T04:18:05.163

Modified: 2026-10-09T04:18:05.163

Link: CVE-2026-107886

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T05:30:08Z

Weaknesses