Описание
The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
Меры по смягчению последствий
Fixed on upstream master branch with commit 0c6842f and for versions 2.4.x with commit 2b1dc17.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | cups | Fix deferred | ||
| Red Hat Enterprise Linux 6 | cups | Fix deferred | ||
| Red Hat Enterprise Linux 7 | cups | Fix deferred | ||
| Red Hat Enterprise Linux 8 | cups | Fix deferred | ||
| Red Hat Enterprise Linux 9 | cups | Fix deferred | ||
| Red Hat Enterprise Linux 9 | rhel9/cups | Fix deferred | ||
| Red Hat OpenShift Container Platform 4 | rhcos/rhcos | Fix deferred | ||
| Red Hat Hardened Images | cups-main-2.4.19-4.1.hum1 | Fixed | RHSA-2026:66600 | 11.09.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
4.3 Medium
CVSS3
Связанные уязвимости
(The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a sour ...)
The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a sour ...
EPSS
4.3 Medium
CVSS3