OpenPrinting CUPS 2.4.20 之前的版本存在一个空指针解引用漏洞,该漏洞由作业创建请求中重复出现的 IPP 组标签引发。在 IPP 解析过程中,会创建带有 IPP_TAG_ZERO 标签的未命名分隔属性,但 函数会将这些分隔符转换为 IPP_TAG_JOB 类型。在作业启动阶段, 随后会对值为 NULL 的属性名称调用 ,从而导致 终止,并中断所有打印队列。当客户端能够访问调度程序,并向一个接受、已启用且支持所提交文档格式的队列提交作业时,一个精心构造的 Print-Job 请求即可触发此崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| OpenPrinting | CUPS | 0 ~ 2.4.20 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-107888 | 5.1 MEDIUM | CUPS<2.4.20空指针解引用致服务终止 |
| CVE-2026-107885 | 3.3 LOW | CUPS<=2.4.20资源耗尽漏洞 |
| CVE-2026-107886 | 2.3 LOW | CUPS<2.4.20双释放致拒绝服务 |
No comments yet