Impact
The vulnerability originates in libcupsfilters’ cfIEEE1284NormalizeMakeModel() function. When processing a printer‑advertised IEEE‑1284 device ID that contains an empty model field, the function enters an infinite loop that constantly consumes CPU resources, resulting in a denial of service.
Affected Systems
The flaw affects systems running Red Hat Enterprise Linux versions 7, 8, 9, and 10 that have libcupsfilters installed; this inference is drawn from the provided workaround regarding cups‑browsed.
Risk and Exploitability
The CVSS score of 7.5 indicates a moderate‑to‑high severity level, while the EPSS score of <1 % suggests a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, implying no publicly known exploits. Attackers would need proximity to the network to broadcast a crafted printer advertisement, after which the target can be overwhelmed by CPU exhaustion and suffer a denial of service.
OpenCVE Enrichment