{"schema_version":"1.7.2","id":"OESA-2026-4139","modified":"2026-09-30T13:46:58Z","published":"2026-09-30T13:46:58Z","upstream":["CVE-2026-87875","CVE-2026-87876"],"summary":"cups security update","details":"CUPS is the standards-based, open source printing system developed by Apple Inc. for UNIX®-like operating systems. CUPS uses the Internet Printing Protocol (IPP) to support printing to local and network printers..\r\n\r\nSecurity Fix(es):\n\nThe cupsUTF32ToUTF8() function in CUPS&apos;s cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.(CVE-2026-87875)\n\nTwo case-insensitive comparisons on request-derived usernames outside the main authorization path in CUPS&apos;s scheduler (printer ACL validation and private-attribute filtering) could allow bypass of username-based access controls in certain configurations.(CVE-2026-87876)","affected":[{"package":{"ecosystem":"openEuler:24.03-LTS-SP4","name":"cups","purl":"pkg:rpm/openEuler/cups&distro=openEuler-24.03-LTS-SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.7-17.oe2403sp4"}]}],"ecosystem_specific":{"aarch64":["cups-2.4.7-17.oe2403sp4.aarch64.rpm","cups-client-2.4.7-17.oe2403sp4.aarch64.rpm","cups-debuginfo-2.4.7-17.oe2403sp4.aarch64.rpm","cups-debugsource-2.4.7-17.oe2403sp4.aarch64.rpm","cups-devel-2.4.7-17.oe2403sp4.aarch64.rpm","cups-ipptool-2.4.7-17.oe2403sp4.aarch64.rpm","cups-libs-2.4.7-17.oe2403sp4.aarch64.rpm","cups-lpd-2.4.7-17.oe2403sp4.aarch64.rpm","cups-printerapp-2.4.7-17.oe2403sp4.aarch64.rpm"],"noarch":["cups-filesystem-2.4.7-17.oe2403sp4.noarch.rpm","cups-help-2.4.7-17.oe2403sp4.noarch.rpm"],"src":["cups-2.4.7-17.oe2403sp4.src.rpm"],"x86_64":["cups-2.4.7-17.oe2403sp4.x86_64.rpm","cups-client-2.4.7-17.oe2403sp4.x86_64.rpm","cups-debuginfo-2.4.7-17.oe2403sp4.x86_64.rpm","cups-debugsource-2.4.7-17.oe2403sp4.x86_64.rpm","cups-devel-2.4.7-17.oe2403sp4.x86_64.rpm","cups-ipptool-2.4.7-17.oe2403sp4.x86_64.rpm","cups-libs-2.4.7-17.oe2403sp4.x86_64.rpm","cups-lpd-2.4.7-17.oe2403sp4.x86_64.rpm","cups-printerapp-2.4.7-17.oe2403sp4.x86_64.rpm"]}}],"references":[{"type":"ADVISORY","url":"https://www.openeuler.org/zh/security/security-bulletins/detail/?id=openEuler-SA-2026-4139"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87875"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87876"}],"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}],"database_specific":{"severity":"Medium"}}
