OpenPrinting CUPS 2.4.20 及更早版本在 cupsdCheckJobs() 函数的提交超时处理机制中存在资源耗尽漏洞。当任意客户端连接存在正在进行的 Send-Document(发送文档)操作时,调度器会暂停对所有待处理作业的超时处理,且并未将该连接与正在检查的作业进行匹配。 允许访问 IPP 服务的客户端可在操作授权前,持有包含已解析的 Send-Document 头部的未完成 HTTP 请求,从而导致无关的未完成作业无法按预期过期。如果允许执行 Create-Job(创建作业)提交,则未完
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenPrinting | CUPS | 0 ~ 2.4.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107888 | 5.1 MEDIUM | CUPS<2.4.20空指针解引用致服务终止 |
| CVE-2026-107890 | 3.3 LOW | CUPS漏洞:空指针解引用致服务崩溃 |
| CVE-2026-107886 | 2.3 LOW | CUPS<2.4.20双释放致拒绝服务 |
No comments yet