{"schema_version":"1.7.2","id":"OESA-2026-1146","modified":"2026-08-06T11:10:11Z","published":"2026-01-16T11:10:11Z","upstream":["CVE-2025-58436","CVE-2025-61915"],"summary":"cups security update","details":"CUPS is the standards-based, open source printing system developed by Apple Inc. for UNIX®-like operating systems. CUPS uses the Internet Printing Protocol (IPP) to support printing to local and network printers.\r\n\r\nSecurity Fix(es):\n\nOpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue has been patched in version 2.4.15.(CVE-2025-58436)\n\nOpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.(CVE-2025-61915)","affected":[{"package":{"ecosystem":"openEuler:24.03-LTS-SP2","name":"cups","purl":"pkg:rpm/openEuler/cups&distro=openEuler-24.03-LTS-SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.7-11.oe2403sp2"}]}],"ecosystem_specific":{"aarch64":["cups-2.4.7-11.oe2403sp2.aarch64.rpm","cups-client-2.4.7-11.oe2403sp2.aarch64.rpm","cups-debuginfo-2.4.7-11.oe2403sp2.aarch64.rpm","cups-debugsource-2.4.7-11.oe2403sp2.aarch64.rpm","cups-devel-2.4.7-11.oe2403sp2.aarch64.rpm","cups-ipptool-2.4.7-11.oe2403sp2.aarch64.rpm","cups-libs-2.4.7-11.oe2403sp2.aarch64.rpm","cups-lpd-2.4.7-11.oe2403sp2.aarch64.rpm","cups-printerapp-2.4.7-11.oe2403sp2.aarch64.rpm"],"noarch":["cups-filesystem-2.4.7-11.oe2403sp2.noarch.rpm","cups-help-2.4.7-11.oe2403sp2.noarch.rpm"],"src":["cups-2.4.7-11.oe2403sp2.src.rpm"],"x86_64":["cups-2.4.7-11.oe2403sp2.x86_64.rpm","cups-client-2.4.7-11.oe2403sp2.x86_64.rpm","cups-debuginfo-2.4.7-11.oe2403sp2.x86_64.rpm","cups-debugsource-2.4.7-11.oe2403sp2.x86_64.rpm","cups-devel-2.4.7-11.oe2403sp2.x86_64.rpm","cups-ipptool-2.4.7-11.oe2403sp2.x86_64.rpm","cups-libs-2.4.7-11.oe2403sp2.x86_64.rpm","cups-lpd-2.4.7-11.oe2403sp2.x86_64.rpm","cups-printerapp-2.4.7-11.oe2403sp2.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-1146"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58436"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61915"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H"}],"database_specific":{"severity":"Medium"}}
