Описание
Security update for libcupsfilters
This update for libcupsfilters fixes the following issues:
- CVE-2026-64611: infinite-loop CPU-exhaustion DoS in cfIEEE1284NormalizeMakeModel on empty MDL field (bsc#1273145).
- CVE-2026-64612: malformed PNG aborts CUPS image filter process (bsc#1273146).
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1273145
- SUSE Bug 1273146
- SUSE CVE CVE-2026-64611 page
- SUSE CVE CVE-2026-64612 page
Описание
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.
Затронутые продукты
Ссылки
- CVE-2026-64611
- SUSE Bug 1273145
Описание
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.
Затронутые продукты
Ссылки
- CVE-2026-64612
- SUSE Bug 1273146