OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17.
{
"cwe_ids": [
"CWE-125",
"CWE-200"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41079.json",
"cna_assigner": "GitHub_M"
}"2026-05-28T11:13:20Z"
[
{
"signature_type": "Line",
"digest": {
"threshold": 0.9,
"line_hashes": [
"299893045949588976139623539753662255133",
"250277918484656917067460661332154754845",
"180926957210100798147957675817561822731",
"328371740011098925653118821188853713521",
"12965106556956194427173249060981454822",
"80893087353804966362527825391315791552",
"176662638266879331245245720019172492324",
"246157329180559496201844320315879132350"
]
},
"deprecated": false,
"id": "CVE-2026-41079-c5b2088d",
"signature_version": "v1",
"target": {
"file": "cups/cups.h"
},
"source": "https://github.com/openprinting/cups/commit/4bd119bbec57885993ab583c79ee5c70be77a7c2"
}
]
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-41079.json"