CVE-2026-107886: Double Free
OpenPrinting CUPS before 2.4.20 contains a double-free in printer-class management. When CUPS-Add-Modify-Class replaces an existing class member list, addclass() frees pclass->printers without clearing the pointer. If subsequent validation fails, the class retains the dangling pointer; CUPS-Delete-Class subsequently frees the same allocation in cupsdDeletePrinter(). A client authorized to modify and delete classes can cause scheduler-wide denial of service. The default policy requires @SYSTEM privileges.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue under the default CUPS policy?
A client must be authorized to modify and delete printer classes. Under the default policy, this requires @SYSTEM privileges, so unauthenticated or ordinary clients are not exposed by default.
What sequence is required to trigger the denial of service?
An authorized client must replace an existing class member list through CUPS-Add-Modify-Class, cause subsequent validation to fail, and then delete the class with CUPS-Delete-Class. This causes the scheduler to free the retained dangling pointer a second time.
What is the practical impact?
Successful exploitation can cause a scheduler-wide denial of service. The provided information does not indicate confidentiality or integrity impact.