SUSE-SU-2026:21850-1

Source
https://www.suse.com/support/update/announcement/2026/suse-su-202621850-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2026:21850-1.json
JSON Data
https://api.test.osv.dev/v1/vulns/SUSE-SU-2026:21850-1
Upstream
CVE (8)
Related
Published
2026-05-26T12:30:35Z
Modified
2026-06-02T18:24:26Z
Summary
Security update for cups
Details

This update for cups fixes the following issues

  • CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup (bsc#1261572).
  • CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (bsc#1261571).
  • CVE-2026-34979: Heap overflow in get_options() (bsc#1261570).
  • CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach lp code execution over the network (bsc#1261569).
  • CVE-2026-34990: Local print admin token disclosure using temporary printers (bsc#1261568).
  • CVE-2026-39314: negative job-password-supported attribute can lead to a denial of service (bsc#1261743).
  • CVE-2026-39316: dangling subscription pointer can lead to a denial of service (bsc#1261742).
  • CVE-2026-41079: crafted SNMP response can lead to stack-based out-of-bounds read and sensitive memory disclosure (bsc#1263116).

Changes for cups:

  • Version upgrade to 2.4.19.

  • Version upgrade to 2.4.18.

  • Version upgrade to 2.4.17:

  • The scheduler followed symbolic links when cleaning out its temporary directory (Issue #1448)
  • Updated cupsFileGetConf and cupsFilePutConf to escape more characters.
  • Updated man page cancel (Issue #984)
  • Updated cupsRasterReadHeader to validate more of the page header values (Issue #1501)
  • Fixed an issue with the class/printer CGI name checking.
  • Fixed infinite loop in http_write() on busy print servers (Issue #827)
  • Fixed potential TLS blocking issues (Issue #1128)
  • Fixed a job history bug in the scheduler (Issue #1440)
  • Fixed notifier logging bug that would result in nul bytes getting into the log (Issue #1450)
  • Fixed possible use-after-free in cupsdReadClient() (Issue #1454)
  • Fixed a document format bug in the IPP backend (Issue #1457)
  • Fixed DRAIN_OUTPUT race condition (Issue #1461)
  • Fixed a bug when then ippFindXxx and ippSetXxx functions were mixed.
  • Fixed the mapping of supply type keywords to SNMP names.
  • Fixed a bug in the IPP backend when SNMP was disabled.
  • Fixed a crash bug in the rastertoepson filter.
  • Fixed a bug in cgiCheckVariables.
  • Fixed handling read/write errors with OpenSSL (Issue #1506)
  • Fixed handling rehandshake error in _httpTLSRead (Issue #1508)
  • Fixed a debug printf bug on Windows (Issue #1529)
  • Fixed a recursion issue with encoding of nested collections (Issue #1539)
  • Fixed parsing of the LimitRequestBody, MaxLogSize, and MaxRequestSize directives in "cupsd.conf" (Issue #1540)
  • Fixed a parsing bug in ipptool (Issue #1542)
  • Fixed blank line detection in the rastertolabel filter (Issue #1545)
  • Fixed httpPeek edge case on compressed streams
References

Affected packages