Executive brief
OpenPrinting CUPS is a widely used open-source printing system for Linux and Unix-like operating systems. A vulnerability in the system's scheduler allows an attacker to send a specially crafted print job that can crash the printing service. This could lead to a denial-of-service, preventing users from printing documents across the network.
Technical details
A heap-based buffer overflow exists in the CUPS scheduler (cupsd) within the `get_options()` function in `scheduler/job.c`. The vulnerability is caused by a discrepancy between how `ipp_length()` calculates the required buffer size for job attributes and how the attributes are actually serialized. Specifically, `ipp_length()` skips URI attributes, but `get_options()` still writes certain URI attributes (such as `job-uuid` and `job-authorization-uri`) to the buffer without performing bounds checks. A remote, unauthenticated attacker can exploit this by submitting a print job with maliciously large URI attributes, leading to memory corruption, a service crash (DoS), or potentially arbitrary code execution. The issue is addressed in version 2.4.17.
Affected products
- OpenPrinting CUPS <= 2.4.16
Timeline
- 2026-03-31: advisory: GitHub Security Advisory published by OpenPrinting
- 2026-04-03: disclosed: CVE-2026-34979 published
- 2026-04-03: patched: Version 2.4.17 released to address the overflow