CVE-2026-41079

Name
CVE-2026-41079
Description
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17.
NVD Severity
unknown
Other trackers
Mailing lists
Exploits
Forges
GitHub (code, issues), Aports (code, issues)

References

Type URI
security-advisories@github.com https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080
security-advisories@github.com https://github.com/OpenPrinting/cups/commit/d7fe0f521ff3b24676511e747b058362b9a20737
security-advisories@github.com https://github.com/OpenPrinting/cups/security/advisories/GHSA-6wpw-g8g6-wvrv

Match rules

CPE URI Source package Min version Max version
cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:* cups >= None < 2.4.17

Vulnerable and fixed packages

Source package Branch Version Maintainer Status
cups edge-main 2.4.16-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.13-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.12-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.11-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.10-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.10-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.7-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.7-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.7-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.7-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.6-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.5-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.4-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.3-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.3-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r7 None possibly vulnerable
cups edge-main 2.4.2-r6 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r5 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r4 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r3 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r2 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.4.2-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups edge-main 2.3.3-r0 None possibly vulnerable
cups edge-main 2.2.12-r0 None possibly vulnerable
cups edge-main 2.2.10-r0 None possibly vulnerable
cups 3.23-main 2.4.16-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.23-main 2.4.13-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.22-main 2.4.16-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.22-main 2.4.11-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.22-main 2.4.10-r1 None possibly vulnerable
cups 3.22-main 2.4.9-r0 None possibly vulnerable
cups 3.22-main 2.4.7-r0 None possibly vulnerable
cups 3.22-main 2.4.2-r7 None possibly vulnerable
cups 3.22-main 2.4.2-r0 None possibly vulnerable
cups 3.22-main 2.3.3-r0 None possibly vulnerable
cups 3.22-main 2.2.12-r0 None possibly vulnerable
cups 3.22-main 2.2.10-r0 None possibly vulnerable
cups 3.21-main 2.4.16-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.21-main 2.4.11-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.21-main 2.4.10-r1 None possibly vulnerable
cups 3.21-main 2.4.9-r0 None possibly vulnerable
cups 3.21-main 2.4.7-r0 None possibly vulnerable
cups 3.21-main 2.4.2-r7 None possibly vulnerable
cups 3.21-main 2.4.2-r0 None possibly vulnerable
cups 3.21-main 2.3.3-r0 None possibly vulnerable
cups 3.21-main 2.2.12-r0 None possibly vulnerable
cups 3.21-main 2.2.10-r0 None possibly vulnerable
cups 3.20-main 2.4.16-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.20-main 2.4.9-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.20-main 2.4.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.20-main 2.4.8-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.20-main 2.4.7-r0 None possibly vulnerable
cups 3.20-main 2.4.2-r7 None possibly vulnerable
cups 3.20-main 2.4.2-r0 None possibly vulnerable
cups 3.20-main 2.3.3-r0 None possibly vulnerable
cups 3.20-main 2.2.12-r0 None possibly vulnerable
cups 3.20-main 2.2.10-r0 None possibly vulnerable
cups 3.19-main 2.4.9-r1 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.19-main 2.4.9-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.19-main 2.4.7-r0 Natanael Copa <ncopa@alpinelinux.org> possibly vulnerable
cups 3.19-main 2.4.2-r7 None possibly vulnerable
cups 3.19-main 2.4.2-r0 None possibly vulnerable
cups 3.19-main 2.3.3-r0 None possibly vulnerable
cups 3.19-main 2.2.12-r0 None possibly vulnerable
cups 3.19-main 2.2.10-r0 None possibly vulnerable