The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
{
"cna_assigner": "redhat",
"cwe_ids": [
"CWE-125"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87875.json"
}"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2026-87875.json"
[
{
"deprecated": false,
"digest": {
"line_hashes": [
"282056344467979101780444780055905123273",
"242845297114462595083827548719364265916",
"334452425735370591807467877279968958301",
"310049462854465423984813608395665679181",
"295662483908832851437989118437492494902",
"266619866730408558549457950541736672631",
"140788628626063102588913235564942920376",
"128791418092717712512335564817177314240",
"63176061219060814614745211299199857710",
"15379611401582992488119874624496328000"
],
"threshold": 0.9
},
"id": "CVE-2026-87875-b56a805c",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/2b1dc178a2d2325135b855142e384f4e8c42d8e4",
"target": {
"file": "cups/transcode.h"
}
},
{
"deprecated": false,
"digest": {
"line_hashes": [
"282056344467979101780444780055905123273",
"242845297114462595083827548719364265916",
"334452425735370591807467877279968958301",
"310049462854465423984813608395665679181",
"295662483908832851437989118437492494902",
"266619866730408558549457950541736672631",
"140788628626063102588913235564942920376",
"238313407615532658675679934214642124834",
"267518714214345622598074251992838695072",
"116120845938343524662087686948682171831"
],
"threshold": 0.9
},
"id": "CVE-2026-87875-c47fbccd",
"signature_type": "Line",
"signature_version": "v1",
"source": "https://github.com/openprinting/cups/commit/0c6842fc615e8afa284136a092da8178abf5f142",
"target": {
"file": "cups/transcode.h"
}
}
]
"2026-09-13T08:02:35Z"