[CLSA-2026:1776768072] cups: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-04-21 10:41:16 UTC
Description:
- CVE-2026-34980: filter control characters from option values in the scheduler to prevent PPD keyword injection via Print-Job - CVE-2026-39314: range check job-password-supported to prevent integer underflow in _ppdCreateFromIPP - CVE-2026-39316: expire per-printer subscriptions before deleting the printer to prevent use-after-free in cupsdDeleteTemporaryPrinters
Updated packages:
  • cups-2.3.3op2-33.el9_6.1.tuxcare.els3.x86_64.rpm
    sha:08a89f7b9a3e8d18fd3871dfd99652fd4ad8b852b736f0ad6a5a6dfed7a956e1
  • cups-client-2.3.3op2-33.el9_6.1.tuxcare.els3.x86_64.rpm
    sha:fc2ce5841846c8fd13c93eb93e215bd4ac6fe00679c52c0d22c60aa48c85f1ca
  • cups-devel-2.3.3op2-33.el9_6.1.tuxcare.els3.i686.rpm
    sha:3d402b3f61c970cc3e995b78a2c6411e04bc43bd5e4a074ff076addd2735fb13
  • cups-devel-2.3.3op2-33.el9_6.1.tuxcare.els3.x86_64.rpm
    sha:51089eda8250ad5063f3367c55bbb9f0214449181d70f5b9254b2625428a3dc1
  • cups-filesystem-2.3.3op2-33.el9_6.1.tuxcare.els3.noarch.rpm
    sha:2210c205808df66a474e6287e428273a1a7d73bb9852e15eceb3a1933074928f
  • cups-ipptool-2.3.3op2-33.el9_6.1.tuxcare.els3.x86_64.rpm
    sha:85feb3c68d4587a235d7c6fc6a671b1922af1d453cee0d1b29feafe7f2aa8e29
  • cups-libs-2.3.3op2-33.el9_6.1.tuxcare.els3.i686.rpm
    sha:0b2ed64baf41d7c686dbb303d5e3661e0456df5e407f85c113bd396cb2052c29
  • cups-libs-2.3.3op2-33.el9_6.1.tuxcare.els3.x86_64.rpm
    sha:b44d24f6fd9f6915a3dae7c474e81724fac782b9bfc64fcdd8e39cef10e804fd
  • cups-lpd-2.3.3op2-33.el9_6.1.tuxcare.els3.x86_64.rpm
    sha:148d2eabf49dc83f3cbbb3fd07c6c8cda6c90f11f064cc83f6d26883bc0ca1df
  • cups-printerapp-2.3.3op2-33.el9_6.1.tuxcare.els3.x86_64.rpm
    sha:4a88c266c7f7b30fb581f9fa1ab0ad308f63dfd775bd81c3861d523197938c2b
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.