USN-7912-1

Source
https://ubuntu.com/security/notices/USN-7912-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-7912-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-7912-1
Upstream
Related
Published
2025-12-04T16:07:04.925041Z
Modified
2025-12-09T07:32:31.517469Z
Summary
cups vulnerability
Details

Johannes Meixner and Paul Zirnik discovered that CUPS incorrectly handled clients that send messages slowly. A remote attacker could possibly use this issue to cause CUPS to stop responding, resulting in a denial of service. (CVE-2025-58436)

In addition, this update fixes a regression introduced in USN-7897-1 which resulted in certain invalid configuration file directives to cause the CUPS daemon to fail to start.

References

Affected packages

Ubuntu:22.04:LTS / cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups@2.4.1op1-1ubuntu4.16?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.1op1-1ubuntu4.16

Affected versions

2.*

2.3.3op2-7ubuntu2
2.4.1op1-1ubuntu1
2.4.1op1-1ubuntu2
2.4.1op1-1ubuntu3
2.4.1op1-1ubuntu4
2.4.1op1-1ubuntu4.1
2.4.1op1-1ubuntu4.2
2.4.1op1-1ubuntu4.4
2.4.1op1-1ubuntu4.6
2.4.1op1-1ubuntu4.7
2.4.1op1-1ubuntu4.8
2.4.1op1-1ubuntu4.9
2.4.1op1-1ubuntu4.10
2.4.1op1-1ubuntu4.11
2.4.1op1-1ubuntu4.12
2.4.1op1-1ubuntu4.15

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2.4.1op1-1ubuntu4.16",
            "binary_name": "cups"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.16",
            "binary_name": "cups-bsd"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.16",
            "binary_name": "cups-client"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.16",
            "binary_name": "cups-common"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.16",
            "binary_name": "cups-core-drivers"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.16",
            "binary_name": "cups-daemon"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.16",
            "binary_name": "cups-ipp-utils"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.16",
            "binary_name": "cups-ppdc"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.16",
            "binary_name": "cups-server-common"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.16",
            "binary_name": "libcups2"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.16",
            "binary_name": "libcups2-dev"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.16",
            "binary_name": "libcupsimage2"
        },
        {
            "binary_version": "2.4.1op1-1ubuntu4.16",
            "binary_name": "libcupsimage2-dev"
        }
    ]
}

Database specific

cves_map

{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-58436"
        }
    ],
    "ecosystem": "Ubuntu:22.04:LTS"
}

Ubuntu:24.04:LTS / cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups@2.4.7-1.2ubuntu7.9?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.7-1.2ubuntu7.9

Affected versions

2.*

2.4.6-0ubuntu3
2.4.7-1.2ubuntu2
2.4.7-1.2ubuntu3
2.4.7-1.2ubuntu7
2.4.7-1.2ubuntu7.1
2.4.7-1.2ubuntu7.2
2.4.7-1.2ubuntu7.3
2.4.7-1.2ubuntu7.4
2.4.7-1.2ubuntu7.7

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2.4.7-1.2ubuntu7.9",
            "binary_name": "cups"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.9",
            "binary_name": "cups-bsd"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.9",
            "binary_name": "cups-client"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.9",
            "binary_name": "cups-common"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.9",
            "binary_name": "cups-core-drivers"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.9",
            "binary_name": "cups-daemon"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.9",
            "binary_name": "cups-ipp-utils"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.9",
            "binary_name": "cups-ppdc"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.9",
            "binary_name": "cups-server-common"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.9",
            "binary_name": "libcups2-dev"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.9",
            "binary_name": "libcups2t64"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.9",
            "binary_name": "libcupsimage2-dev"
        },
        {
            "binary_version": "2.4.7-1.2ubuntu7.9",
            "binary_name": "libcupsimage2t64"
        }
    ]
}

Database specific

cves_map

{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-58436"
        }
    ],
    "ecosystem": "Ubuntu:24.04:LTS"
}

Ubuntu:25.10 / cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups@2.4.12-0ubuntu3.5?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.12-0ubuntu3.5

Affected versions

2.*

2.4.12-0ubuntu1
2.4.12-0ubuntu2
2.4.12-0ubuntu3
2.4.12-0ubuntu3.3

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2.4.12-0ubuntu3.5",
            "binary_name": "cups"
        },
        {
            "binary_version": "2.4.12-0ubuntu3.5",
            "binary_name": "cups-bsd"
        },
        {
            "binary_version": "2.4.12-0ubuntu3.5",
            "binary_name": "cups-client"
        },
        {
            "binary_version": "2.4.12-0ubuntu3.5",
            "binary_name": "cups-common"
        },
        {
            "binary_version": "2.4.12-0ubuntu3.5",
            "binary_name": "cups-core-drivers"
        },
        {
            "binary_version": "2.4.12-0ubuntu3.5",
            "binary_name": "cups-daemon"
        },
        {
            "binary_version": "2.4.12-0ubuntu3.5",
            "binary_name": "cups-ipp-utils"
        },
        {
            "binary_version": "2.4.12-0ubuntu3.5",
            "binary_name": "cups-ppdc"
        },
        {
            "binary_version": "2.4.12-0ubuntu3.5",
            "binary_name": "cups-server-common"
        },
        {
            "binary_version": "2.4.12-0ubuntu3.5",
            "binary_name": "libcups2-dev"
        },
        {
            "binary_version": "2.4.12-0ubuntu3.5",
            "binary_name": "libcups2t64"
        },
        {
            "binary_version": "2.4.12-0ubuntu3.5",
            "binary_name": "libcupsimage2-dev"
        },
        {
            "binary_version": "2.4.12-0ubuntu3.5",
            "binary_name": "libcupsimage2t64"
        }
    ]
}

Database specific

cves_map

{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-58436"
        }
    ],
    "ecosystem": "Ubuntu:25.10"
}

Ubuntu:25.04 / cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups@2.4.12-0ubuntu1.6?arch=source&distro=plucky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.12-0ubuntu1.6

Affected versions

2.*

2.4.10-1ubuntu2
2.4.11-0ubuntu1
2.4.11-0ubuntu2
2.4.12-0ubuntu1
2.4.12-0ubuntu1.1
2.4.12-0ubuntu1.4

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "2.4.12-0ubuntu1.6",
            "binary_name": "cups"
        },
        {
            "binary_version": "2.4.12-0ubuntu1.6",
            "binary_name": "cups-bsd"
        },
        {
            "binary_version": "2.4.12-0ubuntu1.6",
            "binary_name": "cups-client"
        },
        {
            "binary_version": "2.4.12-0ubuntu1.6",
            "binary_name": "cups-common"
        },
        {
            "binary_version": "2.4.12-0ubuntu1.6",
            "binary_name": "cups-core-drivers"
        },
        {
            "binary_version": "2.4.12-0ubuntu1.6",
            "binary_name": "cups-daemon"
        },
        {
            "binary_version": "2.4.12-0ubuntu1.6",
            "binary_name": "cups-ipp-utils"
        },
        {
            "binary_version": "2.4.12-0ubuntu1.6",
            "binary_name": "cups-ppdc"
        },
        {
            "binary_version": "2.4.12-0ubuntu1.6",
            "binary_name": "cups-server-common"
        },
        {
            "binary_version": "2.4.12-0ubuntu1.6",
            "binary_name": "libcups2-dev"
        },
        {
            "binary_version": "2.4.12-0ubuntu1.6",
            "binary_name": "libcups2t64"
        },
        {
            "binary_version": "2.4.12-0ubuntu1.6",
            "binary_name": "libcupsimage2-dev"
        },
        {
            "binary_version": "2.4.12-0ubuntu1.6",
            "binary_name": "libcupsimage2t64"
        }
    ]
}

Database specific

cves_map

{
    "cves": [
        {
            "severity": [
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "CVSS_V3",
                    "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"
                },
                {
                    "type": "Ubuntu",
                    "score": "medium"
                }
            ],
            "id": "CVE-2025-58436"
        }
    ],
    "ecosystem": "Ubuntu:25.04"
}