Echo: cups: security update to 2.4.18-1

medium Tenable Self-Hosted Container Security Plugin ID 465764

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In
versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g.,
rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that
is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode
0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This
PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the
job cache and previously queued jobs disappear. At time of publication, there are no publicly available
patches. (CVE-2026-34978)

Solution

Update the cups library and its related packages to version 2.4.18-1 or later.

See Also

https://advisory.echohq.com/cve/CVE-2026-34978

Plugin Details

Severity: Medium

ID: 465764

Version: Revision 1.1

Type: Local

Published: 10/2/2026

Updated: 10/2/2026

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.79

CVSS v2

Risk Factor: Medium

Base Score: 6.4

Temporal Score: 5

Vector: CVSS2#AV:N/AC:L/Au:N/C:N/I:P/A:P

CVSS Score Source: CVE-2026-34978

CVSS v3

Risk Factor: Medium

Base Score: 6.5

Temporal Score: 5.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/4/2026

Vulnerability Publication Date: 4/3/2026

Reference Information

CVE: CVE-2026-34978