Impact
The vulnerability originates in the cupsUTF32ToUTF8() routine, which fails to enforce a length check on its source buffer. The resulting out‑of‑bounds read can expose heap memory contents as the function processes SNMP supply‑description fields. Thus the primary impact is potential disclosure of sensitive information residing in memory. No code execution or denial of service is reported for this vector, and the weakness is classified as CWE‑125.
Affected Systems
Red Hat Enterprise Linux releases 6 through 10, Red Hat Hardened Images, and Red Hat OpenShift Container Platform 4 are affected. These platforms ship CUPS including the vulnerable module. The description does not list specific minor versions, so any iteration containing the unpatched CUPS package is at risk.
Risk and Exploitability
The CVSS score of 4.3 indicates moderate risk. EPSS is not available, so the likelihood of exploitation is unknown, but the vulnerability has not yet been catalogued in CISA KEV. The issue is reachable through SNMP supply‑description parsing, which may be triggered by an attacker sending crafted SNMP queries to a CUPS server.
OpenCVE Enrichment