Description
OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference caused by repeated IPP group tags in job-creation requests. IPP parsing creates unnamed separator attributes with IPP_TAG_ZERO, but add_job() converts these separators to IPP_TAG_JOB. During job startup, get_options()/ipp_length() subsequently calls strlen() on a NULL attribute name, terminating cupsd and disrupting all queues. A single crafted Print-Job request can trigger the crash when the client can reach the scheduler and submit jobs to an accepting, enabled queue supporting the submitted document format. Anonymous submission is possible when permitted by listener and access-control configuration.
Published: 2026-10-09
Score: 3.3 Low
EPSS: n/a
KEV: No
Impact: Denial of Service
Action: Apply patch
AI Analysis

Impact

OpenPrinting CUPS before version 2.4.20 contains a NULL pointer dereference that is triggered by a crafted Print-Job request with repeated IPP group tags. The IPP parser creates unnamed separator attributes tagged IPP_TAG_ZERO, which are later converted to IPP_TAG_JOB during job creation. When the scheduler processes these attributes, a call to strlen() is made on a NULL attribute name, causing the cups daemon to crash and all queues to become unavailable. The crash is a direct result of a pointer dereference and impacts only the availability of the print service, with no data leakage or code execution. The likely attack vector is a remote IPP Print-Job request sent to the CUPS scheduler; anonymous submission is possible when listener and access‑control permit it.

Affected Systems

The affected products are OpenPrinting CUPS versions earlier than 2.4.20. This includes all systems that run the CUPS print service via the OpenPrinting project and have IPP job submission enabled. There are no restrictions on operating system or hardware, so any typical Linux or Unix deployment hosting CUPS before the 2.4.20 release is potentially impacted.

Risk and Exploitability

The CVSS score of 3.3 signals low severity for confidentiality and integrity, yet the impact on availability is significant because a single crafted request can crash the service. The EPSS score is not available, indicating no current data on a high likelihood of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Attackers would need the ability to reach the CUPS scheduler and submit an IPP Print-Job; anonymous submission is possible when listener and access‑control configuration allow it, so unauthenticated remote attackers could exploit this if the printer is accessible over a network interface that accepts jobs.

Generated by OpenCVE AI on October 9, 2026 at 05:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenPrinting CUPS to version 2.4.20 or newer
  • Disable or restrict IPP job submission on interfaces that allow anonymous access
  • Enforce authentication for Print-Job requests or limit job submission to trusted users

Generated by OpenCVE AI on October 9, 2026 at 05:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 06:15:00 +0000

Type Values Removed Values Added
Title Null Pointer Dereference in CUPS via Malformed IPP Group Tags

Fri, 09 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference caused by repeated IPP group tags in job-creation requests. IPP parsing creates unnamed separator attributes with IPP_TAG_ZERO, but add_job() converts these separators to IPP_TAG_JOB. During job startup, get_options()/ipp_length() subsequently calls strlen() on a NULL attribute name, terminating cupsd and disrupting all queues. A single crafted Print-Job request can trigger the crash when the client can reach the scheduler and submit jobs to an accepting, enabled queue supporting the submitted document format. Anonymous submission is possible when permitted by listener and access-control configuration.
First Time appeared Openprinting
Openprinting cups
Weaknesses CWE-476
CPEs cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*
Vendors & Products Openprinting
Openprinting cups
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Openprinting Cups
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-09T04:10:52.643Z

Reserved: 2026-10-09T04:10:51.860Z

Link: CVE-2026-107890

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T05:16:44.730

Modified: 2026-10-09T05:16:44.730

Link: CVE-2026-107890

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T06:15:18Z

Weaknesses