Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

openSUSE-SU-2026:21893-1

Опубликовано: 20 сент. 2026
Источник: suse-cvrf

Описание

Security update for cups

This update for cups fixes the following issue:

  • CVE-2026-87875: heap out-of-bounds read in cupsUTF32ToUTF8() due to missing source-length bound can be reached via the SNMP supply-description parsing (bsc#1279945).

Список пакетов

openSUSE Leap 16.0
cups-2.4.19-160000.2.1
cups-client-2.4.19-160000.2.1
cups-config-2.4.19-160000.2.1
cups-ddk-2.4.19-160000.2.1
cups-devel-2.4.19-160000.2.1
libcups2-2.4.19-160000.2.1
libcupsimage2-2.4.19-160000.2.1

Описание

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.


Затронутые продукты
openSUSE Leap 16.0:cups-2.4.19-160000.2.1
openSUSE Leap 16.0:cups-client-2.4.19-160000.2.1
openSUSE Leap 16.0:cups-config-2.4.19-160000.2.1
openSUSE Leap 16.0:cups-ddk-2.4.19-160000.2.1

Ссылки