CVE-2026-107885: Low severity OpenPrinting CUPS vulnerability
OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdCheckJobs(). The scheduler suppresses timeout processing for all pending jobs whenever any client connection has an in-flight Send-Document operation, without matching that connection to the job being examined. A client allowed to reach the IPP service can hold an incomplete HTTP request containing parsed Send-Document headers before operation authorization, preventing unrelated incomplete jobs from expiring. Where Create-Job submission is allowed, incomplete jobs can accumulate until MaxJobs is exhausted and further legitimate print submissions are rejected. The suppression ends when the held connection closes.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Deployments are exposed if clients can reach the IPP service and Create-Job submission is allowed. An attacker needs only low-privilege network access to the service.
What does an attacker need to do to trigger the resource exhaustion?
The attacker holds an incomplete HTTP request with parsed Send-Document headers open before operation authorization. This suppresses timeout processing for unrelated incomplete jobs until the held connection closes.
What is the operational impact?
Incomplete jobs can accumulate until MaxJobs is exhausted. At that point, legitimate print submissions are rejected.
What can be done if patching is not immediately possible?
Limit access to the IPP service and restrict Create-Job submission where possible. Closing the malicious or stalled Send-Document connection ends the timeout suppression.