Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:3935-1

Опубликовано: 03 сент. 2026
Источник: suse-cvrf

Описание

Security update for cups-filters

This update for cups-filters fixes the following issues:

  • CVE-2026-64611: user who controls an IEEE-1284 device ID consumed by cfIEEE1284GetMakeModel can drive cfIEEE1284NormalizeMakeModel into an infinite loop (bsc#1273145).
  • CVE-2026-64612: authenticated client that can submit an image print job can abort the CUPS filter process by supplying a malformed PNG (bsc#1273146).

Список пакетов

SUSE Linux Enterprise Module for Basesystem 15 SP7
cups-filters-1.25.0-150200.3.31.1
cups-filters-devel-1.25.0-150200.3.31.1

Описание

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:cups-filters-1.25.0-150200.3.31.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:cups-filters-devel-1.25.0-150200.3.31.1

Ссылки

Описание

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.


Затронутые продукты
SUSE Linux Enterprise Module for Basesystem 15 SP7:cups-filters-1.25.0-150200.3.31.1
SUSE Linux Enterprise Module for Basesystem 15 SP7:cups-filters-devel-1.25.0-150200.3.31.1

Ссылки