It was discovered that CUPS did not properly filter control characters in IPP string attributes and PPD keywords. An unauthenticated attacker could exploit this to execute arbitrary code as the lp user on systems with shared target queues.
{
"binaries": [
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "cups"
},
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "cups-bsd"
},
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "cups-client"
},
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "cups-common"
},
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "cups-core-drivers"
},
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "cups-daemon"
},
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "cups-ipp-utils"
},
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "cups-ppdc"
},
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "cups-server-common"
},
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "libcups2"
},
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "libcupscgi1"
},
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "libcupsimage2"
},
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "libcupsmime1"
},
{
"binary_version": "2.1.3-4ubuntu0.11+esm13",
"binary_name": "libcupsppdc1"
}
],
"availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"
}
{
"ecosystem": "Ubuntu:Pro:16.04:LTS",
"cves": [
{
"severity": [
{
"score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N",
"type": "CVSS_V4"
},
{
"score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
],
"id": "CVE-2026-34980"
}
]
}
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8578-1.json"