Описание
ELSA-2026-56965: libcupsfilters security update (MODERATE)
[1:2.0.0-13]
- RHEL-214027 CVE-2026-64611 libcupsfilters: Fix infinite loop and empty device_ids in ieee1284
[1:2.0.0-12]
- RHEL-212655 CVE-2026-64612 libcupsfilters: Handle libpng errors via longjmp()/setjmp() to prevent process abort on malformed PNG
Обновленные пакеты
Oracle Linux 10
Oracle Linux aarch64
libcupsfilters
2.0.0-13.el10_2
Oracle Linux x86_64
libcupsfilters
2.0.0-13.el10_2
Связанные CVE
Связанные уязвимости
CVSS3: 7.5
ubuntu
около 2 месяцев назад
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.