CVE-2026-107655

medium

Description

A flaw was found in CUPS. When processing embedded job ticket comments within documents, the service improperly handles specific IPP attributes, causing an unhandled null pointer dereference. An unauthenticated attacker permitted to submit jobs to a shared printer queue can send a crafted Internet Printing Protocol (IPP) request to crash the print daemon, resulting in a temporary Denial of Service (DoS) for all printing services.

References

https://github.com/OpenPrinting/cups/security/advisories/GHSA-58wv-9ffm-5w78

https://github.com/OpenPrinting/cups/commit/25d6830

https://github.com/OpenPrinting/cups/commit/12237ad

https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-95572

https://bugzilla.redhat.com/show_bug.cgi?id=2548399

https://access.redhat.com/security/cve/CVE-2026-107655

Details

Source: Mitre, NVD

Published: 2026-10-09

Updated: 2026-10-09

Risk Information

CVSS v2

Base Score: 2.1

Vector: CVSS2#AV:L/AC:L/Au:N/C:N/I:N/A:P

Severity: Low

CVSS v3

Base Score: 4

Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Severity: Medium

EPSS

EPSS: 0.00128