Описание
Security update for cups-filters
This update for cups-filters fixes the following issues:
- CVE-2026-64611: user who controls an IEEE-1284 device ID consumed by
cfIEEE1284GetMakeModelcan drivecfIEEE1284NormalizeMakeModelinto an infinite loop (bsc#1273145). - CVE-2026-64612: authenticated client that can submit an image print job can abort the CUPS filter process by supplying a malformed PNG (bsc#1273146).
Список пакетов
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
Ссылки
- Link for SUSE-SU-2026:3918-1
- E-Mail link for SUSE-SU-2026:3918-1
- SUSE Security Ratings
- SUSE Bug 1273145
- SUSE Bug 1273146
- SUSE CVE CVE-2026-64611 page
- SUSE CVE CVE-2026-64612 page
Описание
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.
Затронутые продукты
Ссылки
- CVE-2026-64611
- SUSE Bug 1273145
Описание
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.
Затронутые продукты
Ссылки
- CVE-2026-64612
- SUSE Bug 1273146