UBUNTU-CVE-2026-34978

Source
https://ubuntu.com/security/CVE-2026-34978
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34978.json
JSON Data
https://api.test.osv.dev/v1/vulns/UBUNTU-CVE-2026-34978
Upstream
Published
2026-04-03T22:16:00Z
Modified
2026-04-13T14:33:38.309368Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L CVSS Calculator
  • Ubuntu - medium
Summary
[none]
Details

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, the RSS notifier allows .. path traversal in notify-recipient-uri (e.g., rss:///../job.cache), letting a remote IPP client write RSS XML bytes outside CacheDir/rss (anywhere that is lp-writable). In particular, because CacheDir is group-writable by default (typically root:lp and mode 0770), the notifier (running as lp) can replace root-managed state files via temp-file + rename(). This PoC clobbers CacheDir/job.cache with RSS XML, and after restarting cupsd the scheduler fails to parse the job cache and previously queued jobs disappear. At time of publication, there are no publicly available patches.

References

Affected packages

Ubuntu:22.04:LTS
cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups@2.4.1op1-1ubuntu4.16?arch=source&distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.3.3op2-7ubuntu2
2.4.1op1-1ubuntu1
2.4.1op1-1ubuntu2
2.4.1op1-1ubuntu3
2.4.1op1-1ubuntu4
2.4.1op1-1ubuntu4.1
2.4.1op1-1ubuntu4.2
2.4.1op1-1ubuntu4.4
2.4.1op1-1ubuntu4.6
2.4.1op1-1ubuntu4.7
2.4.1op1-1ubuntu4.8
2.4.1op1-1ubuntu4.9
2.4.1op1-1ubuntu4.10
2.4.1op1-1ubuntu4.11
2.4.1op1-1ubuntu4.12
2.4.1op1-1ubuntu4.15
2.4.1op1-1ubuntu4.16

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "cups",
            "binary_version": "2.4.1op1-1ubuntu4.16"
        },
        {
            "binary_name": "cups-bsd",
            "binary_version": "2.4.1op1-1ubuntu4.16"
        },
        {
            "binary_name": "cups-client",
            "binary_version": "2.4.1op1-1ubuntu4.16"
        },
        {
            "binary_name": "cups-common",
            "binary_version": "2.4.1op1-1ubuntu4.16"
        },
        {
            "binary_name": "cups-core-drivers",
            "binary_version": "2.4.1op1-1ubuntu4.16"
        },
        {
            "binary_name": "cups-daemon",
            "binary_version": "2.4.1op1-1ubuntu4.16"
        },
        {
            "binary_name": "cups-ipp-utils",
            "binary_version": "2.4.1op1-1ubuntu4.16"
        },
        {
            "binary_name": "cups-ppdc",
            "binary_version": "2.4.1op1-1ubuntu4.16"
        },
        {
            "binary_name": "cups-server-common",
            "binary_version": "2.4.1op1-1ubuntu4.16"
        },
        {
            "binary_name": "libcups2",
            "binary_version": "2.4.1op1-1ubuntu4.16"
        },
        {
            "binary_name": "libcups2-dev",
            "binary_version": "2.4.1op1-1ubuntu4.16"
        },
        {
            "binary_name": "libcupsimage2",
            "binary_version": "2.4.1op1-1ubuntu4.16"
        },
        {
            "binary_name": "libcupsimage2-dev",
            "binary_version": "2.4.1op1-1ubuntu4.16"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34978.json"
Ubuntu:24.04:LTS
cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups@2.4.7-1.2ubuntu7.9?arch=source&distro=noble

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.4.6-0ubuntu3
2.4.7-1.2ubuntu2
2.4.7-1.2ubuntu3
2.4.7-1.2ubuntu7
2.4.7-1.2ubuntu7.1
2.4.7-1.2ubuntu7.2
2.4.7-1.2ubuntu7.3
2.4.7-1.2ubuntu7.4
2.4.7-1.2ubuntu7.7
2.4.7-1.2ubuntu7.9

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "cups",
            "binary_version": "2.4.7-1.2ubuntu7.9"
        },
        {
            "binary_name": "cups-bsd",
            "binary_version": "2.4.7-1.2ubuntu7.9"
        },
        {
            "binary_name": "cups-client",
            "binary_version": "2.4.7-1.2ubuntu7.9"
        },
        {
            "binary_name": "cups-common",
            "binary_version": "2.4.7-1.2ubuntu7.9"
        },
        {
            "binary_name": "cups-core-drivers",
            "binary_version": "2.4.7-1.2ubuntu7.9"
        },
        {
            "binary_name": "cups-daemon",
            "binary_version": "2.4.7-1.2ubuntu7.9"
        },
        {
            "binary_name": "cups-ipp-utils",
            "binary_version": "2.4.7-1.2ubuntu7.9"
        },
        {
            "binary_name": "cups-ppdc",
            "binary_version": "2.4.7-1.2ubuntu7.9"
        },
        {
            "binary_name": "cups-server-common",
            "binary_version": "2.4.7-1.2ubuntu7.9"
        },
        {
            "binary_name": "libcups2-dev",
            "binary_version": "2.4.7-1.2ubuntu7.9"
        },
        {
            "binary_name": "libcups2t64",
            "binary_version": "2.4.7-1.2ubuntu7.9"
        },
        {
            "binary_name": "libcupsimage2-dev",
            "binary_version": "2.4.7-1.2ubuntu7.9"
        },
        {
            "binary_name": "libcupsimage2t64",
            "binary_version": "2.4.7-1.2ubuntu7.9"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34978.json"
Ubuntu:25.10
cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups@2.4.12-0ubuntu3.5?arch=source&distro=questing

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.4.12-0ubuntu1
2.4.12-0ubuntu2
2.4.12-0ubuntu3
2.4.12-0ubuntu3.3
2.4.12-0ubuntu3.5

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "cups",
            "binary_version": "2.4.12-0ubuntu3.5"
        },
        {
            "binary_name": "cups-bsd",
            "binary_version": "2.4.12-0ubuntu3.5"
        },
        {
            "binary_name": "cups-client",
            "binary_version": "2.4.12-0ubuntu3.5"
        },
        {
            "binary_name": "cups-common",
            "binary_version": "2.4.12-0ubuntu3.5"
        },
        {
            "binary_name": "cups-core-drivers",
            "binary_version": "2.4.12-0ubuntu3.5"
        },
        {
            "binary_name": "cups-daemon",
            "binary_version": "2.4.12-0ubuntu3.5"
        },
        {
            "binary_name": "cups-ipp-utils",
            "binary_version": "2.4.12-0ubuntu3.5"
        },
        {
            "binary_name": "cups-ppdc",
            "binary_version": "2.4.12-0ubuntu3.5"
        },
        {
            "binary_name": "cups-server-common",
            "binary_version": "2.4.12-0ubuntu3.5"
        },
        {
            "binary_name": "libcups2-dev",
            "binary_version": "2.4.12-0ubuntu3.5"
        },
        {
            "binary_name": "libcups2t64",
            "binary_version": "2.4.12-0ubuntu3.5"
        },
        {
            "binary_name": "libcupsimage2-dev",
            "binary_version": "2.4.12-0ubuntu3.5"
        },
        {
            "binary_name": "libcupsimage2t64",
            "binary_version": "2.4.12-0ubuntu3.5"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34978.json"
Ubuntu:Pro:16.04:LTS
cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups@2.1.3-4ubuntu0.11+esm12?arch=source&distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.1.0-4ubuntu3
2.1.0-5
2.1.0-6
2.1.0-6ubuntu1
2.1.0-7
2.1.2-1
2.1.2-2
2.1.3-1
2.1.3-1build1
2.1.3-3
2.1.3-4
2.1.3-4ubuntu0.2
2.1.3-4ubuntu0.3
2.1.3-4ubuntu0.4
2.1.3-4ubuntu0.5
2.1.3-4ubuntu0.6
2.1.3-4ubuntu0.7
2.1.3-4ubuntu0.8
2.1.3-4ubuntu0.9
2.1.3-4ubuntu0.10
2.1.3-4ubuntu0.11
2.1.3-4ubuntu0.11+esm1
2.1.3-4ubuntu0.11+esm2
2.1.3-4ubuntu0.11+esm3
2.1.3-4ubuntu0.11+esm4
2.1.3-4ubuntu0.11+esm5
2.1.3-4ubuntu0.11+esm6
2.1.3-4ubuntu0.11+esm7
2.1.3-4ubuntu0.11+esm8
2.1.3-4ubuntu0.11+esm9
2.1.3-4ubuntu0.11+esm11
2.1.3-4ubuntu0.11+esm12

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "cups",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "cups-bsd",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "cups-client",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "cups-common",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "cups-core-drivers",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "cups-daemon",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "cups-ipp-utils",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "cups-ppdc",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "cups-server-common",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "libcups2",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "libcups2-dev",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "libcupscgi1",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "libcupscgi1-dev",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "libcupsimage2",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "libcupsimage2-dev",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "libcupsmime1",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "libcupsmime1-dev",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "libcupsppdc1",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        },
        {
            "binary_name": "libcupsppdc1-dev",
            "binary_version": "2.1.3-4ubuntu0.11+esm12"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34978.json"
Ubuntu:Pro:18.04:LTS
cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups@2.2.7-1ubuntu2.10+esm10?arch=source&distro=esm-infra/bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.2.4-7ubuntu2
2.2.5-2
2.2.6-2
2.2.6-3
2.2.6-4
2.2.6-5
2.2.7-1ubuntu1
2.2.7-1ubuntu2
2.2.7-1ubuntu2.1
2.2.7-1ubuntu2.2
2.2.7-1ubuntu2.3
2.2.7-1ubuntu2.4
2.2.7-1ubuntu2.5
2.2.7-1ubuntu2.6
2.2.7-1ubuntu2.7
2.2.7-1ubuntu2.8
2.2.7-1ubuntu2.9
2.2.7-1ubuntu2.10
2.2.7-1ubuntu2.10+esm1
2.2.7-1ubuntu2.10+esm2
2.2.7-1ubuntu2.10+esm3
2.2.7-1ubuntu2.10+esm4
2.2.7-1ubuntu2.10+esm5
2.2.7-1ubuntu2.10+esm6
2.2.7-1ubuntu2.10+esm7
2.2.7-1ubuntu2.10+esm9
2.2.7-1ubuntu2.10+esm10

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "cups",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "cups-bsd",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "cups-client",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "cups-common",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "cups-core-drivers",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "cups-daemon",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "cups-ipp-utils",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "cups-ppdc",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "cups-server-common",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "libcups2",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "libcups2-dev",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "libcupscgi1",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "libcupsimage2",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "libcupsimage2-dev",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "libcupsmime1",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        },
        {
            "binary_name": "libcupsppdc1",
            "binary_version": "2.2.7-1ubuntu2.10+esm10"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34978.json"
Ubuntu:Pro:20.04:LTS
cups

Package

Name
cups
Purl
pkg:deb/ubuntu/cups@2.3.1-9ubuntu1.9+esm4?arch=source&distro=esm-infra/focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

2.*
2.2.12-2ubuntu1
2.3.0-6
2.3.0-7
2.3.0-7ubuntu1
2.3.1-1ubuntu1
2.3.1-2
2.3.1-4
2.3.1-7
2.3.1-9ubuntu1
2.3.1-9ubuntu1.1
2.3.1-9ubuntu1.2
2.3.1-9ubuntu1.3
2.3.1-9ubuntu1.4
2.3.1-9ubuntu1.5
2.3.1-9ubuntu1.6
2.3.1-9ubuntu1.7
2.3.1-9ubuntu1.8
2.3.1-9ubuntu1.9
2.3.1-9ubuntu1.9+esm1
2.3.1-9ubuntu1.9+esm3
2.3.1-9ubuntu1.9+esm4

Ecosystem specific

{
    "binaries": [
        {
            "binary_name": "cups",
            "binary_version": "2.3.1-9ubuntu1.9+esm4"
        },
        {
            "binary_name": "cups-bsd",
            "binary_version": "2.3.1-9ubuntu1.9+esm4"
        },
        {
            "binary_name": "cups-client",
            "binary_version": "2.3.1-9ubuntu1.9+esm4"
        },
        {
            "binary_name": "cups-common",
            "binary_version": "2.3.1-9ubuntu1.9+esm4"
        },
        {
            "binary_name": "cups-core-drivers",
            "binary_version": "2.3.1-9ubuntu1.9+esm4"
        },
        {
            "binary_name": "cups-daemon",
            "binary_version": "2.3.1-9ubuntu1.9+esm4"
        },
        {
            "binary_name": "cups-ipp-utils",
            "binary_version": "2.3.1-9ubuntu1.9+esm4"
        },
        {
            "binary_name": "cups-ppdc",
            "binary_version": "2.3.1-9ubuntu1.9+esm4"
        },
        {
            "binary_name": "cups-server-common",
            "binary_version": "2.3.1-9ubuntu1.9+esm4"
        },
        {
            "binary_name": "libcups2",
            "binary_version": "2.3.1-9ubuntu1.9+esm4"
        },
        {
            "binary_name": "libcups2-dev",
            "binary_version": "2.3.1-9ubuntu1.9+esm4"
        },
        {
            "binary_name": "libcupsimage2",
            "binary_version": "2.3.1-9ubuntu1.9+esm4"
        },
        {
            "binary_name": "libcupsimage2-dev",
            "binary_version": "2.3.1-9ubuntu1.9+esm4"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-34978.json"