CVE-2026-41079

EUVD-2026-25574
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
4.3 MEDIUM
ADJACENT_NETWORK
LOW
NONE
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 6%
Affected Products (NVD)
VendorProductVersion
openprintingcups
𝑥
< 2.4.17
𝑥
= Vulnerable software versions
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
cups
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-client
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-client-debuginfo
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-debuginfo
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-debugsource
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-devel
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-filesystem
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-ipptool
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-ipptool-debuginfo
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-libs
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-libs-debuginfo
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-lpd
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-lpd-debuginfo
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-printerapp
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
cups-printerapp-debuginfo
Amazon Linux 2023
1:2.4.19-1.amzn2023.0.1
fixed
Azure Linux logo
Azure Linux Releases
Azure Package
Release
cups
Azure Linux 3.0
0:2.4.18-1.azl3
fixed