MGASA-2026-0201

Source
https://advisories.mageia.org/MGASA-2026-0201.html
Import Source
https://advisories.mageia.org/MGASA-2026-0201.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2026-0201
Upstream
Published
2026-06-12T23:28:19Z
Modified
2026-06-12T23:49:00.005405484Z
Summary
Updated cups packages fix security vulnerabilities
Details

CVE-2026-27447, Authorization bypass via case-insensitive group-member lookup. CVE-2026-39314, Integer underflow in _ppdCreateFromIPP causes root cupsd crash via negative job-password-supported CVE-2026-39316, Use-after-free in cupsdDeleteTemporaryPrinters via dangling subscription pointer CVE-2026-34978, Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (and clobbering of job.cache) CVE-2026-34979, Heap overflow in get_options() CVE-2026-34980, Shared PostScript queue lets anonymous Print-Job requests reach lpcode execution over the network CVE-2026-34990, Local print admin token disclosure using temporary printers. Heap out-of-bounds read in SNMP supply-level polling leaks stack memory to authenticated users. Out-of-bounds heap read in cupsdSetPrinterAttr marker-types parsing

References
Credits

Affected packages

Mageia:9 / cups

Package

Name
cups
Purl
pkg:rpm/mageia/cups?arch=source&distro=mageia-9

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.4.6-1.10.mga9

Ecosystem specific

{
    "section": "core"
}

Database specific

source
"https://advisories.mageia.org/MGASA-2026-0201.json"