CVE-2026-107888: Null Pointer Dereference
OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create refers to a temporary printer that has been automatically deleted. Temporary-printer cleanup can remove the destination without canceling its held jobs, and the scheduler dereferences the NULL result of cupsdFindDest() while checking holdingnewjobs. This terminates cupsd and interrupts all queues managed by that process. In some plausible scenarios, an unprivileged submission can trigger this.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenPrinting CUPSto a version that resolves this vulnerability.Fixed in 2.4.20
Event History
Frequently Asked Questions
Which deployments are exposed to this issue?
OpenPrinting CUPS versions before 2.4.20 are affected. Exposure requires use of temporary printers and a held job associated with a temporary printer that is later automatically deleted.
What must occur for an attacker to trigger the denial of service?
A job marked job-held-on-create must refer to a temporary printer, the temporary-printer cleanup must remove that destination without canceling the held job, and cupsd must subsequently check held new jobs. In plausible scenarios, an unprivileged user can submit a job that contributes to these conditions.
What is the operational impact if the issue is triggered?
The cupsd scheduler terminates when it dereferences the missing destination. This interrupts every print queue managed by that cupsd process.