在 OpenPrinting CUPS 2.4.20 之前的版本中,打印机类管理存在一个双重释放(double-free)漏洞。当 CUPS-Add-Modify-Class 替换现有类成员列表时,add_class() 函数会释放 pclass->printers,但未将指针置空。如果后续验证失败,该类仍将保留悬空指针;随后,CUPS-Delete-Class 在 cupsdDeletePrinter() 中会再次释放同一块内存。任何被授权修改和删除类的客户端均可导致调度器范围内的拒绝服务(DoS)攻击。默认策略
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenPrinting | CUPS | 1.4.8 ~ 2.4.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107888 | 5.1 MEDIUM | CUPS<2.4.20空指针解引用致服务终止 |
| CVE-2026-107885 | 3.3 LOW | CUPS<=2.4.20资源耗尽漏洞 |
| CVE-2026-107890 | 3.3 LOW | CUPS漏洞:空指针解引用致服务崩溃 |
No comments yet