CVE-2025-61915

medium

Description

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.

References

https://github.com/OpenPrinting/cups/security/advisories/GHSA-hxm8-vfpq-jrfc

https://github.com/OpenPrinting/cups/releases/tag/v2.4.15

https://github.com/OpenPrinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0

http://www.openwall.com/lists/oss-security/2025/11/27/5

Details

Source: Mitre, NVD

Published: 2025-11-29

Updated: 2025-12-04

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:L/AC:L/Au:M/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 6.7

Vector: CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Severity: Medium

EPSS

EPSS: 0.00011