EulerOS 2.0 SP15 : cups (EulerOS-SA-2026-2878)

medium Nessus Plugin ID 332933

Synopsis

The remote EulerOS host is missing a security update.

Description

According to the versions of the cups packages installed, the EulerOS installation on the remote host is affected by the following vulnerabilities :

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17.(CVE-2026-41079)

Tenable has extracted the preceding description block directly from the EulerOS cups security advisory.

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected cups packages.

See Also

http://www.nessus.org/u?60e9fa32

Plugin Details

Severity: Medium

ID: 332933

File Name: EulerOS_SA-2026-2878.nasl

Version: 1.1

Type: Local

Published: 8/6/2026

Updated: 8/6/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.66

CVSS v2

Risk Factor: Medium

Base Score: 4.8

Temporal Score: 3.8

Vector: CVSS2#AV:A/AC:L/Au:N/C:P/I:N/A:P

CVSS Score Source: CVE-2026-41079

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.9

Vector: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:huawei:euleros:2.0, p-cpe:/a:huawei:euleros:cups-devel, p-cpe:/a:huawei:euleros:cups-libs

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/EulerOS/release, Host/EulerOS/rpm-list, Host/EulerOS/sp

Excluded KB Items: Host/EulerOS/uvp_version

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/6/2026

Vulnerability Publication Date: 4/24/2026

Reference Information

CVE: CVE-2026-41079