在 OpenPrinting CUPS 2.4.20 之前的版本中,存在一个空指针解引用漏洞,位于 函数中。当某个被标记为“创建时保留”(job-held-on-create)的作业引用了一个已被自动删除的临时打印机时,就会触发此问题。临时打印机清理机制可能在未取消其关联的保留作业的情况下删除目标打印机,而调度程序在检查“保留的新作业”时,会调用 并解引用其返回的 NULL 值。这将导致 cupsd 进程终止,并中断该进程所管理的所有打印队列。在某些可行的场景下,未经权限认证的用户即可触发此漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenPrinting | CUPS | 0 ~ 2.4.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107885 | 3.3 LOW | CUPS<=2.4.20资源耗尽漏洞 |
| CVE-2026-107890 | 3.3 LOW | CUPS漏洞:空指针解引用致服务崩溃 |
| CVE-2026-107886 | 2.3 LOW | CUPS<2.4.20双释放致拒绝服务 |
No comments yet