CVE-2025-61915

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.
Buffer Underflow
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
GitHub_MCNA
6 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
VendorProductVersion
openprintingcups
𝑥
< 2.4.15
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cups
bullseye
postponed
trixie
no-dsa
bookworm
no-dsa
bullseye (security)
vulnerable
bookworm (security)
vulnerable
trixie (security)
vulnerable
forky
2.4.15-1
fixed
sid
2.4.16-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cups
questing
Fixed 2.4.12-0ubuntu3.3
released
plucky
Fixed 2.4.12-0ubuntu1.4
released
noble
Fixed 2.4.7-1.2ubuntu7.7
released
jammy
Fixed 2.4.1op1-1ubuntu4.15
released
focal
Fixed 2.3.1-9ubuntu1.9+esm3
released
bionic
Fixed 2.2.7-1ubuntu2.10+esm9
released
xenial
Fixed 2.1.3-4ubuntu0.11+esm11
released