Описание
Security update for cups
This update for cups fixes the following issue:
- CVE-2026-87875: heap out-of-bounds read in
cupsUTF32ToUTF8()due to missing source-length bound can be reached via the SNMP supply-description parsing (bsc#1279945).
Список пакетов
openSUSE Leap 16.0
cups-2.4.19-160000.2.1
cups-client-2.4.19-160000.2.1
cups-config-2.4.19-160000.2.1
cups-ddk-2.4.19-160000.2.1
cups-devel-2.4.19-160000.2.1
libcups2-2.4.19-160000.2.1
libcupsimage2-2.4.19-160000.2.1
Ссылки
- SUSE Security Ratings
- SUSE Bug 1279945
- SUSE CVE CVE-2026-87875 page
Описание
The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
Затронутые продукты
openSUSE Leap 16.0:cups-2.4.19-160000.2.1
openSUSE Leap 16.0:cups-client-2.4.19-160000.2.1
openSUSE Leap 16.0:cups-config-2.4.19-160000.2.1
openSUSE Leap 16.0:cups-ddk-2.4.19-160000.2.1
Ссылки
- CVE-2026-87875
- SUSE Bug 1279945