Synopsis
The remote openSUSE host is missing one or more security updates.
Description
The remote openSUSE 16 host has packages installed that are affected by multiple vulnerabilities as referenced in the openSUSE-SU-2026:21850-1 advisory.
Changes in cups-filters:
- CVE-2026-64611: Fixed Infinite-loop CPU-exhaustion DoS in cfIEEE1284NormalizeMakeModel on empty MDL field.
A user who controls an IEEE-1284 device ID consumed by `cfIEEE1284GetMakeModel` can drive `cfIEEE1284NormalizeMakeModel` into an infinite loop.
(bsc#1273145,GHSA-rcq7-rv5g-j3r4)
- CVE-2026-64612: Fixed Malformed PNG aborts CUPS image filter process (missing libpng setjmp recovery) A authenticated client that can submit an image print job can abort the CUPS filter process by supplying a malformed PNG.
(bsc#1273146,GHSA-7mxj-cfq5-84ch)
- Provide cups-browsed as separated cups-filters-cups-browsed sub-package so users can uninstall this sub-package to completely avoid the generic security risk of cups-browsed.
cups-browsed auto-creates local print queues for printers which are announced via DNS-SD. It is a generic security risk when a service (cups-browsed.service) accepts any (possibly malicious) incoming information from any host in the local network (i.e. any DNS-SD announcements) and from that information it auto-creates print queue configurations for CUPS (where its server program cupsd runs as root).
For more information see the openSUSE support database article https://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings
- Fixed a regression Error about PPD file during 'driverless' printer setup (boo#1256868) and ppd pull out from [driverless] printer feature broken (bsc#1256977)
- unbreak qpdf [bsc#1253678]
- CVE-2024-47176: Fixed cups-browsed binds to UDP INADDR_ANY:631 (bsc#1230939) and to avoid CVE-2024-47850 cups-browsed can be abused to initiate remote DDoS against third-party targets (bsc#1231294) by removing legacy CUPS Browsing support in cups-browsed (introduced 2012) which is no longer needed nowadays.
CUPS browsing was removed from CUPS since version 1.6.
Legacy CUPS Browsing is a generic security risk, see the section Automated print queue setup via cups-browsed in https://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings
- CVE-2024-47076: Fixed lack of input sanitization in cfGetPrinterAttributes5 (bsc#1230937)
- CVE-2024-47175: Fixed lack of input sanitization in _ppdCreateFromIPP() (bsc#1230932)
- In general regarding CUPS and cups-browsed security issues see https://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings
Tenable has extracted the preceding description block directly from the SUSE security advisory.
Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.
Solution
Update the affected cups-filters, cups-filters-cups-browsed and / or cups-filters-devel packages.
Plugin Details
File Name: openSUSE-2026-21850-1.nasl
Agent: unix
Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus
Risk Information
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C
Vulnerability Information
CPE: cpe:/o:novell:opensuse:16.0, p-cpe:/a:novell:opensuse:cups-filters-cups-browsed, p-cpe:/a:novell:opensuse:cups-filters-devel, p-cpe:/a:novell:opensuse:cups-filters
Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list
Exploit Ease: Exploits are available
Patch Publication Date: 9/14/2026
Vulnerability Publication Date: 9/26/2024
Exploitable With
Core Impact
Metasploit (CUPS IPP Attributes LAN Remote Code Execution)