Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-64611

Опубликовано: 14 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.

Отчет

A Moderate denial-of-service vulnerability in libcupsfilters allows network attackers to exhaust CPU resources by sending malformed IEEE-1284 device IDs. Red Hat rates this as Moderate because the vulnerable component, cups-browsed, is disabled by default in RHEL.

Меры по смягчению последствий

If automatic network printer discovery is not strictly necessary for your environment, stopping the service completely eliminates the vulnerable attack surface.If you must use cups-browsed for legitimate operational reasons, you should prevent untrusted networks from feeding data to the daemon.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cups-filtersAffected
Red Hat Enterprise Linux 10libcupsfiltersAffected
Red Hat Enterprise Linux 7cups-filtersAffected
Red Hat Enterprise Linux 8cups-filtersAffected
Red Hat Enterprise Linux 9cups-filtersAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-835
https://bugzilla.redhat.com/show_bug.cgi?id=2502799libcupsfilters: cups-filters: libcupsfilters: CPU exhaustion via infinite loop in cfIEEE1284NormalizeMakeModel()

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
8 дней назад

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.

CVSS3: 7.5
nvd
8 дней назад

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.

CVSS3: 7.5
debian
8 дней назад

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() ...

CVSS3: 7.5
github
8 дней назад

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.

CVSS3: 7.5
fstec
8 дней назад

Уязвимость функции cfIEEE1284NormalizeMakeModel() библиотеки для сервера печати Libcupsfilters, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3