Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21818-1

Опубликовано: 09 сент. 2026
Источник: suse-cvrf

Описание

Security update for libcupsfilters

This update for libcupsfilters fixes the following issues:

  • CVE-2026-64611: infinite-loop CPU-exhaustion DoS in cfIEEE1284NormalizeMakeModel on empty MDL field (bsc#1273145).
  • CVE-2026-64612: malformed PNG aborts CUPS image filter process (bsc#1273146).

Список пакетов

openSUSE Leap 16.0
libcupsfilters-2.1.1-160000.3.1
libcupsfilters-devel-2.1.1-160000.3.1
libcupsfilters2-2.1.1-160000.3.1

Описание

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.


Затронутые продукты
openSUSE Leap 16.0:libcupsfilters-2.1.1-160000.3.1
openSUSE Leap 16.0:libcupsfilters-devel-2.1.1-160000.3.1
openSUSE Leap 16.0:libcupsfilters2-2.1.1-160000.3.1

Ссылки

Описание

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job.


Затронутые продукты
openSUSE Leap 16.0:libcupsfilters-2.1.1-160000.3.1
openSUSE Leap 16.0:libcupsfilters-devel-2.1.1-160000.3.1
openSUSE Leap 16.0:libcupsfilters2-2.1.1-160000.3.1

Ссылки
Уязвимость openSUSE-SU-2026:21818-1