Description
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.
Published: 2026-07-20
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw in libcupsfilters and cups‑filters lies in the PNG image reading routine, which creates a libpng reader without installing an error‑recovery handler. When the CUPS image filter process handles a malformed PNG, it aborts, immediately terminating the in‑flight print job. An unauthenticated attacker can exploit this by submitting a specially crafted PNG print job, resulting in a denial of service for that job. The vulnerability is classified as CWE‑248, improper error‑handling, and based on the description it is inferred that it does not compromise confidentiality or integrity of data; the impact remains localized to the interrupted printing job.

Affected Systems

Red Hat Enterprise Linux 7, 8, 9, and 10 hosts that include the vulnerable libcupsfilters and cups‑filters packages are affected. No specific version numbers are disclosed; any distribution release that ships with these libraries may be impacted.

Risk and Exploitability

The CVSS score of 7.5 indicates high severity. The EPSS score of less than 1 % and the absence from the CISA KEV catalog suggest that publicly documented exploitation has not occurred, but the flaw is remotely exploitable. An attacker who can send a print job to the CUPS service can submit a crafted PNG file to trigger the abort, causing a denial of service for that job. The impact is limited to the affected print job, and repeated abuse is inferred to potentially degrade overall availability of the printing subsystem.

Generated by OpenCVE AI on August 3, 2026 at 01:18 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.


OpenCVE Recommended Actions

  • Apply any Red Hat update that addresses libcupsfilters or cups‑filters when it becomes available.
  • If no patch is released, disable or uninstall the cups‑filters package to remove the vulnerable image filtering code.
  • Restrict access to the CUPS service so that only authenticated or trusted users can submit jobs, and enable audit logging to detect abnormal job abort events.
  • Red Hat currently offers no practical workaround; remain vigilant for future advisories.

Generated by OpenCVE AI on August 3, 2026 at 01:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 18:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.
Title Libcupsfilters: cups-filters: libcupsfilters: cups image filter process abort via malformed png
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-248
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-21T17:31:26.245Z

Reserved: 2026-07-20T11:15:34.675Z

Link: CVE-2026-64612

cve-icon Vulnrichment

Updated: 2026-07-20T18:21:50.217Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:30:16Z

Weaknesses