CVE-2026-55453

Public on 2026-10-09
Modified on 2026-10-09
Description
A malicious or attacker-controlled IPP printer can return a crafted text printer-status attribute, such as marker-message, containing embedded newline characters. The CUPS ipp backend reports this remote printer attribute to the scheduler through the backend stderr/status stream. The current quoting helper escapes quotes and backslashes, but it does not reject or encode LF/CR. As a result, attacker-controlled printer status text can create a new backend status line beginning with PPD:.

NOTE: https://github.com/OpenPrinting/cups/security/advisories/GHSA-7hqf-mfhx-7r3v
NOTE: Fixed by: https://github.com/OpenPrinting/cups/commit/d41cf0616688721e9d435d54118c4c8a36ed596a (v2.4.20)
Severity
Medium severity
Medium
See what this means
CVSS v3 Base Score
5.8
See breakdown

Affected Packages

Platform Package Release Date Advisory Status
Amazon Linux 2 - Core cups Pending Fix
Amazon Linux 2023 cups Pending Fix
Amazon Linux 2027 Preview cups Pending Fix
Amazon Linux 2027 Preview cups-browsed Not Affected
Amazon Linux 2 - Core cups-filters Not Affected
Amazon Linux 2023 cups-filters Not Affected
Amazon Linux 2027 Preview cups-filters Not Affected
Amazon Linux 2 - Core cups-pk-helper Not Affected
Amazon Linux 2023 cups-pk-helper Not Affected
Amazon Linux 2027 Preview cups-pk-helper Not Affected
Amazon Linux 2027 Preview libcupsfilters Not Affected
Amazon Linux 2 - Core python-cups Not Affected
Amazon Linux 2023 python-cups Not Affected
Amazon Linux 2027 Preview python-cups Not Affected

CVSS Scores

Score Type Score Vector
Amazon Linux CVSSv3 5.8 CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L