Impact
OpenPrinting CUPS before version 2.4.20 contains a NULL pointer dereference that is triggered by a crafted Print-Job request with repeated IPP group tags. The IPP parser creates unnamed separator attributes tagged IPP_TAG_ZERO, which are later converted to IPP_TAG_JOB during job creation. When the scheduler processes these attributes, a call to strlen() is made on a NULL attribute name, causing the cups daemon to crash and all queues to become unavailable. The crash is a direct result of a pointer dereference and impacts only the availability of the print service, with no data leakage or code execution. The likely attack vector is a remote IPP Print-Job request sent to the CUPS scheduler; anonymous submission is possible when listener and access‑control permit it.
Affected Systems
The affected products are OpenPrinting CUPS versions earlier than 2.4.20. This includes all systems that run the CUPS print service via the OpenPrinting project and have IPP job submission enabled. There are no restrictions on operating system or hardware, so any typical Linux or Unix deployment hosting CUPS before the 2.4.20 release is potentially impacted.
Risk and Exploitability
The CVSS score of 3.3 signals low severity for confidentiality and integrity, yet the impact on availability is significant because a single crafted request can crash the service. The EPSS score is not available, indicating no current data on a high likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to reach the CUPS scheduler and submit an IPP Print-Job; anonymous submission is possible when listener and access‑control configuration allow it, so unauthenticated remote attackers could exploit this if the printer is accessible over a network interface that accepts jobs.
OpenCVE Enrichment