发现 CUPS 中存在一个漏洞。在处理文档中嵌入的作业票(job ticket)注释时,该服务未能正确处理某些 IPP 属性,导致出现未处理的空指针解引用(null pointer dereference)。未被身份验证但被允许向共享打印机队列提交打印作业的攻击者,可以发送精心构造的 Internet 打印协议(IPP)请求,从而致使打印守护进程崩溃,造成所有打印服务暂时不可用,形成拒绝服务(DoS)攻击。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Red Hat | Red Hat Enterprise Linux 10 | - |
cpe:/o:redhat:enterprise_linux:10
|
|
| Red Hat | Red Hat Enterprise Linux 6 | - |
cpe:/o:redhat:enterprise_linux:6
|
|
| Red Hat | Red Hat Enterprise Linux 7 | - |
cpe:/o:redhat:enterprise_linux:7
|
|
| Red Hat | Red Hat Enterprise Linux 8 | - |
cpe:/o:redhat:enterprise_linux:8
|
|
| Red Hat | Red Hat Enterprise Linux 9 | - |
cpe:/o:redhat:enterprise_linux:9
|
|
| Red Hat | Red Hat Hardened Images | - |
cpe:/a:redhat:hummingbird:1
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107935 | 9.3 CRITICAL | Gvisor-tap-vsock: gvisor-tap-vsock: unathenticated arbitrary file deletion on the host via |
| CVE-2026-107889 | 5.5 MEDIUM | Keycloak-services: keycloak-services: stored xss on login page via kcsanitize bypass |
No comments yet