CVE-2026-107888
Public on 2026-10-09
Modified on 2026-10-10
Description
OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create refers to a temporary printer that has been automatically deleted. Temporary-printer cleanup can remove the destination without canceling its held jobs, and the scheduler dereferences the NULL result of cupsdFindDest() while checking holding_new_jobs. This terminates cupsd and interrupts all queues managed by that process. In some plausible scenarios, an unprivileged submission can trigger this.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | cups | Not Affected | ||
| Amazon Linux 2023 | cups | Pending Fix | ||
| Amazon Linux 2027 Preview | cups | Pending Fix | ||
| Amazon Linux 2027 Preview | cups-browsed | Not Affected | ||
| Amazon Linux 2 - Core | cups-filters | Not Affected | ||
| Amazon Linux 2023 | cups-filters | Not Affected | ||
| Amazon Linux 2027 Preview | cups-filters | Not Affected | ||
| Amazon Linux 2 - Core | cups-pk-helper | Not Affected | ||
| Amazon Linux 2023 | cups-pk-helper | Not Affected | ||
| Amazon Linux 2027 Preview | cups-pk-helper | Not Affected | ||
| Amazon Linux 2027 Preview | libcupsfilters | Not Affected | ||
| Amazon Linux 2 - Core | python-cups | Not Affected | ||
| Amazon Linux 2023 | python-cups | Not Affected | ||
| Amazon Linux 2027 Preview | python-cups | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 5.1 | CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H |