CVE-2025-58436

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue has been patched in version 2.4.15.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.1 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
GitHub_MCNA
5.1 MEDIUM
LOCAL
HIGH
NONE
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 1%
VendorProductVersion
openprintingcups
𝑥
< 2.4.15
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cups
bullseye
postponed
trixie
no-dsa
bookworm
no-dsa
bullseye (security)
vulnerable
bookworm (security)
vulnerable
trixie (security)
vulnerable
forky
2.4.15-1
fixed
sid
2.4.16-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cups
questing
Fixed 2.4.12-0ubuntu3.5
released
plucky
Fixed 2.4.12-0ubuntu1.6
released
noble
Fixed 2.4.7-1.2ubuntu7.9
released
jammy
Fixed 2.4.1op1-1ubuntu4.16
released
focal
Fixed 2.3.1-9ubuntu1.9+esm4
released
bionic
Fixed 2.2.7-1ubuntu2.10+esm10
released
xenial
Fixed 2.1.3-4ubuntu0.11+esm12
released