Description
OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create refers to a temporary printer that has been automatically deleted. Temporary-printer cleanup can remove the destination without canceling its held jobs, and the scheduler dereferences the NULL result of cupsdFindDest() while checking holding_new_jobs. This terminates cupsd and interrupts all queues managed by that process. In some plausible scenarios, an unprivileged submission can trigger this.
Published: 2026-10-09
Score: 5.1 Medium
EPSS: n/a
KEV: No
Impact: Denial of Service (service crash)
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a NULL pointer dereference in the CUPSD job scheduler that occurs when a held job refers to a temporary printer that has been automatically deleted. This causes CUPSD to terminate, disrupting all managed print queues. The description explicitly states that an unprivileged submission can trigger this failure, leading to a denial‑of‑service condition for the printing service.

Affected Systems

OpenPrinting CUPS installations running any version prior to 2.4.20 are affected. The issue is tied to the handling of jobs that have the job‑held‑on‑create flag in environments that use temporary printers. Versions 2.4.20 and later include the official fix.

Risk and Exploitability

The CVSS score of 5.1 places this vulnerability in the medium range, and no EPSS value is available, indicating limited publicly known exploitation data. It is not currently featured in CISA’s KEV catalog. The likely attack vector is local or network‑based unprivileged submissions that reference a temporary printer; upon triggering the NULL dereference, the service terminates, impacting availability for all users.

Generated by OpenCVE AI on October 9, 2026 at 06:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to CUPS 2.4.20 or a later release that applies the NULL pointer dereference fix.
  • If an upgrade is not feasible, disable the job‑held‑on‑create feature or prevent the creation of temporary printers that can be referenced by held jobs, using configuration directives in cupsd.conf.
  • Monitor CUPSD logs for job submissions to non‑existent printers and enforce stricter access controls to limit unprivileged users from creating jobs that could trigger the defect.

Generated by OpenCVE AI on October 9, 2026 at 06:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Title NULL Pointer Dereference in CUPS Job Scheduler Leads to Service Crash

Fri, 09 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create refers to a temporary printer that has been automatically deleted. Temporary-printer cleanup can remove the destination without canceling its held jobs, and the scheduler dereferences the NULL result of cupsdFindDest() while checking holding_new_jobs. This terminates cupsd and interrupts all queues managed by that process. In some plausible scenarios, an unprivileged submission can trigger this.
First Time appeared Openprinting
Openprinting cups
Weaknesses CWE-476
CPEs cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*
Vendors & Products Openprinting
Openprinting cups
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Openprinting Cups
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-09T04:06:55.424Z

Reserved: 2026-10-09T04:06:54.629Z

Link: CVE-2026-107888

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T05:16:44.407

Modified: 2026-10-09T05:16:44.407

Link: CVE-2026-107888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T06:30:17Z

Weaknesses