Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-64612

Опубликовано: 14 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.

Отчет

This Moderate denial-of-service flaw in libcupsfilters and cups-filters allows an unauthenticated attacker to crash the CUPS image filter process. By submitting a specially crafted PNG print job, an attacker can trigger an abort, impacting only the in-flight print job rather than the overall CUPS service stability.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10cups-filtersNot affected
Red Hat Enterprise Linux 10libcupsfiltersAffected
Red Hat Enterprise Linux 7cups-filtersOut of support scope
Red Hat Enterprise Linux 8cups-filtersAffected
Red Hat Enterprise Linux 9cups-filtersAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-248
https://bugzilla.redhat.com/show_bug.cgi?id=2502801libcupsfilters: cups-filters: libcupsfilters: CUPS image filter process abort via malformed PNG

EPSS

Процентиль: 28%
0.0035
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
12 дней назад

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.

CVSS3: 7.5
nvd
12 дней назад

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.

CVSS3: 7.5
debian
12 дней назад

A flaw was found in libcupsfilters and cups-filters. The PNG image rea ...

CVSS3: 7.5
github
12 дней назад

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.

EPSS

Процентиль: 28%
0.0035
Низкий

7.5 High

CVSS3