Impact
The flaw in libcupsfilters and cups‑filters lies in the PNG image reading routine, which creates a libpng reader without installing an error‑recovery handler. When the CUPS image filter process handles a malformed PNG, it aborts, immediately terminating the in‑flight print job. An unauthenticated attacker can exploit this by submitting a specially crafted PNG print job, resulting in a denial of service for that job. The vulnerability is classified as CWE‑248, improper error‑handling, and based on the description it is inferred that it does not compromise confidentiality or integrity of data; the impact remains localized to the interrupted printing job.
Affected Systems
Red Hat Enterprise Linux 7, 8, 9, and 10 hosts that include the vulnerable libcupsfilters and cups‑filters packages are affected. No specific version numbers are disclosed; any distribution release that ships with these libraries may be impacted.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score of less than 1 % and the absence from the CISA KEV catalog suggest that publicly documented exploitation has not occurred, but the flaw is remotely exploitable. An attacker who can send a print job to the CUPS service can submit a crafted PNG file to trigger the abort, causing a denial of service for that job. The impact is limited to the affected print job, and repeated abuse is inferred to potentially degrade overall availability of the printing subsystem.
OpenCVE Enrichment