[CLSA-2026:1776767380] cups: Fix of 3 CVEs
Type:
security
Severity:
Important
Release date:
2026-04-21 10:29:44 UTC
Description:
- CVE-2026-34980: filter control characters from option values in the scheduler to prevent PPD keyword injection via Print-Job - CVE-2026-39314: range check job-password-supported to prevent integer underflow in _ppdCreateFromIPP - CVE-2026-39316: expire per-printer subscriptions before deleting the printer to prevent use-after-free in cupsdDeleteTemporaryPrinters
Updated packages:
  • cups-2.3.3op2-16.el9_2.1.tuxcare.els10.x86_64.rpm
    sha:6199cfcb576dfaaf0fe8cc0286bd9f224d7a5e17ec3175bbac42ea1e233f3f27
  • cups-client-2.3.3op2-16.el9_2.1.tuxcare.els10.x86_64.rpm
    sha:f91b4801b5324c30191817d324dfca7af5dfd01a4660941b93cf2c6e9022a33d
  • cups-devel-2.3.3op2-16.el9_2.1.tuxcare.els10.i686.rpm
    sha:947e621604aa02a1f8616b7f9c37d3abcc970503ac229a0afb68ce9057d9883e
  • cups-devel-2.3.3op2-16.el9_2.1.tuxcare.els10.x86_64.rpm
    sha:407ae6c477414fc8dbcc6db71a809022b188bd58f4693d666248a5b93298dbe4
  • cups-filesystem-2.3.3op2-16.el9_2.1.tuxcare.els10.noarch.rpm
    sha:64f4cdaf830b6f62f99f811cd5a92202234a1b7ea52a907a51cb17573c95d824
  • cups-ipptool-2.3.3op2-16.el9_2.1.tuxcare.els10.x86_64.rpm
    sha:f10ecd8a638b6c23f201a95ca6d393a310b20232bf9708890e96130a835c420f
  • cups-libs-2.3.3op2-16.el9_2.1.tuxcare.els10.i686.rpm
    sha:fc591b28d5f9cb0e3dfb969e5f39d7f3a839c0504bf09b886f71f9845c4fdadf
  • cups-libs-2.3.3op2-16.el9_2.1.tuxcare.els10.x86_64.rpm
    sha:660ad42a03bbf49e1bcece05d2f94d8f2479e295545f84c796bfd052b42da1b6
  • cups-lpd-2.3.3op2-16.el9_2.1.tuxcare.els10.x86_64.rpm
    sha:0e5df0fb2c2b54c1121458de6adc0bcd0a81617ce5a215af565b720e6ef0a58b
  • cups-printerapp-2.3.3op2-16.el9_2.1.tuxcare.els10.x86_64.rpm
    sha:a4e5491377c75602dd0aa845f64972a3154a2c7ddc2f4b83dd8fbbe4e7071236
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.