AZL-106890

See a problem?
Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106890.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-106890
Upstream
Published
2026-10-09T05:16:44Z
Modified
2026-10-10T14:17:32Z
Summary
CVE-2026-107888 affecting package cups 2.4.19-1
Details

OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create refers to a temporary printer that has been automatically deleted. Temporary-printer cleanup can remove the destination without canceling its held jobs, and the scheduler dereferences the NULL result of cupsdFindDest() while checking holding_new_jobs. This terminates cupsd and interrupts all queues managed by that process. In some plausible scenarios, an unprivileged submission can trigger this.

References

Affected packages

Azure Linux:3 / cups

Package

Name
cups
Purl
pkg:rpm/azure-linux/cups

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.4.19-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-106890.json"