USN-8578-1

Source
https://ubuntu.com/security/notices/USN-8578-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8578-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-8578-1
Upstream
Related
Published
2026-07-21T12:57:09Z
Modified
2026-07-21T23:14:34.729114987Z
Summary
CUPS vulnerability
Details

It was discovered that CUPS did not properly filter control characters in IPP string attributes and PPD keywords. An unauthenticated attacker could exploit this to execute arbitrary code as the lp user on systems with shared target queues.

References

Affected packages

Ubuntu:Pro:16.04:LTS / cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups?arch=source&distro=esm-infra-legacy%2Fxenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.1.3-4ubuntu0.11+esm13

Affected versions

2.*
2.1.0-4ubuntu3
2.1.0-5
2.1.0-6
2.1.0-6ubuntu1
2.1.0-7
2.1.2-1
2.1.2-2
2.1.3-1
2.1.3-1build1
2.1.3-3
2.1.3-4
2.1.3-4ubuntu0.2
2.1.3-4ubuntu0.3
2.1.3-4ubuntu0.4
2.1.3-4ubuntu0.5
2.1.3-4ubuntu0.6
2.1.3-4ubuntu0.7
2.1.3-4ubuntu0.8
2.1.3-4ubuntu0.9
2.1.3-4ubuntu0.10
2.1.3-4ubuntu0.11
2.1.3-4ubuntu0.11+esm1
2.1.3-4ubuntu0.11+esm2
2.1.3-4ubuntu0.11+esm3
2.1.3-4ubuntu0.11+esm4
2.1.3-4ubuntu0.11+esm5
2.1.3-4ubuntu0.11+esm6
2.1.3-4ubuntu0.11+esm7
2.1.3-4ubuntu0.11+esm8
2.1.3-4ubuntu0.11+esm9
2.1.3-4ubuntu0.11+esm11
2.1.3-4ubuntu0.11+esm12

Ecosystem specific

{
    "binaries": [
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "cups"
        },
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "cups-bsd"
        },
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "cups-client"
        },
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "cups-common"
        },
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "cups-core-drivers"
        },
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "cups-daemon"
        },
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "cups-ipp-utils"
        },
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "cups-ppdc"
        },
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "cups-server-common"
        },
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "libcups2"
        },
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "libcupscgi1"
        },
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "libcupsimage2"
        },
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "libcupsmime1"
        },
        {
            "binary_version": "2.1.3-4ubuntu0.11+esm13",
            "binary_name": "libcupsppdc1"
        }
    ],
    "availability": "Available with Ubuntu Pro with Legacy support add-on: https://ubuntu.com/pro"
}

Database specific

cves_map
{
    "ecosystem": "Ubuntu:Pro:16.04:LTS",
    "cves": [
        {
            "severity": [
                {
                    "score": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N",
                    "type": "CVSS_V4"
                },
                {
                    "score": "CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
                    "type": "CVSS_V3"
                },
                {
                    "score": "medium",
                    "type": "Ubuntu"
                }
            ],
            "id": "CVE-2026-34980"
        }
    ]
}
source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-8578-1.json"