OESA-2026-1146

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2026-1146
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2026-1146.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2026-1146
Upstream
Published
2026-01-16T11:10:11Z
Modified
2026-08-18T01:19:28.122286638Z
Severity
  • 6.0 (Medium) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H CVSS Calculator
Summary
cups security update
Details

CUPS is the standards-based, open source printing system developed by Apple Inc. for UNIX®-like operating systems. CUPS uses the Internet Printing Protocol (IPP) to support printing to local and network printers.

Security Fix(es):

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue has been patched in version 2.4.15.(CVE-2025-58436)

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.(CVE-2025-61915)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:24.03-LTS-SP2 / cups

Package

Name
cups
Purl
pkg:rpm/openEuler/cups&distro=openEuler-24.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.7-11.oe2403sp2

Ecosystem specific

{
    "x86_64": [
        "cups-2.4.7-11.oe2403sp2.x86_64.rpm",
        "cups-client-2.4.7-11.oe2403sp2.x86_64.rpm",
        "cups-debuginfo-2.4.7-11.oe2403sp2.x86_64.rpm",
        "cups-debugsource-2.4.7-11.oe2403sp2.x86_64.rpm",
        "cups-devel-2.4.7-11.oe2403sp2.x86_64.rpm",
        "cups-ipptool-2.4.7-11.oe2403sp2.x86_64.rpm",
        "cups-libs-2.4.7-11.oe2403sp2.x86_64.rpm",
        "cups-lpd-2.4.7-11.oe2403sp2.x86_64.rpm",
        "cups-printerapp-2.4.7-11.oe2403sp2.x86_64.rpm"
    ],
    "aarch64": [
        "cups-2.4.7-11.oe2403sp2.aarch64.rpm",
        "cups-client-2.4.7-11.oe2403sp2.aarch64.rpm",
        "cups-debuginfo-2.4.7-11.oe2403sp2.aarch64.rpm",
        "cups-debugsource-2.4.7-11.oe2403sp2.aarch64.rpm",
        "cups-devel-2.4.7-11.oe2403sp2.aarch64.rpm",
        "cups-ipptool-2.4.7-11.oe2403sp2.aarch64.rpm",
        "cups-libs-2.4.7-11.oe2403sp2.aarch64.rpm",
        "cups-lpd-2.4.7-11.oe2403sp2.aarch64.rpm",
        "cups-printerapp-2.4.7-11.oe2403sp2.aarch64.rpm"
    ],
    "src": [
        "cups-2.4.7-11.oe2403sp2.src.rpm"
    ],
    "noarch": [
        "cups-filesystem-2.4.7-11.oe2403sp2.noarch.rpm",
        "cups-help-2.4.7-11.oe2403sp2.noarch.rpm"
    ]
}

Database specific

source
"https://repo.openeuler.org/security/data/osv/OESA-2026-1146.json"