Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-107655— Cups: null pointer dereference via embedded job ticket comments allows remote denial of service

Quick assessment

Affected
Red Hat Red Hat Enterprise Linux 10
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

发现 CUPS 中存在一个漏洞。在处理文档中嵌入的作业票(job ticket)注释时,该服务未能正确处理某些 IPP 属性,导致出现未处理的空指针解引用(null pointer dereference)。未被身份验证但被允许向共享打印机队列提交打印作业的攻击者,可以发送精心构造的 Internet 打印协议(IPP)请求,从而致使打印守护进程崩溃,造成所有打印服务暂时不可用,形成拒绝服务(DoS)攻击。

CVSS 4.0 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-107655

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Cups: null pointer dereference via embedded job ticket comments allows remote denial of service
Source: CVE Program / CVE List V5
Vulnerability Description
A flaw was found in CUPS. When processing embedded job ticket comments within documents, the service improperly handles specific IPP attributes, causing an unhandled null pointer dereference. An unauthenticated attacker permitted to submit jobs to a shared printer queue can send a crafted Internet Printing Protocol (IPP) request to crash the print daemon, resulting in a temporary Denial of Service (DoS) for all printing services.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
空指针解引用
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Red Hat Red Hat Enterprise Linux 10 - cpe:/o:redhat:enterprise_linux:10
Red Hat Red Hat Enterprise Linux 6 - cpe:/o:redhat:enterprise_linux:6
Red Hat Red Hat Enterprise Linux 7 - cpe:/o:redhat:enterprise_linux:7
Red Hat Red Hat Enterprise Linux 8 - cpe:/o:redhat:enterprise_linux:8
Red Hat Red Hat Enterprise Linux 9 - cpe:/o:redhat:enterprise_linux:9
Red Hat Red Hat Hardened Images - cpe:/a:redhat:hummingbird:1

II. Public POCs for CVE-2026-107655

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-107655

请登录查看更多情报信息。

Other References for CVE-2026-107655 (5)

Same Patch Batch · Red Hat · 2026-10-09 · 3 CVEs total

CVE-2026-107935 9.3 CRITICAL Gvisor-tap-vsock: gvisor-tap-vsock: unathenticated arbitrary file deletion on the host via
CVE-2026-107889 5.5 MEDIUM Keycloak-services: keycloak-services: stored xss on login page via kcsanitize bypass

IV. Related Vulnerabilities

V. Comments for CVE-2026-107655

No comments yet


Leave a comment