CVE-2026-107890: Null Pointer Dereference
OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference caused by repeated IPP group tags in job-creation requests. IPP parsing creates unnamed separator attributes with IPPTAGZERO, but addjob() converts these separators to IPPTAGJOB. During job startup, getoptions()/ipplength() subsequently calls strlen() on a NULL attribute name, terminating cupsd and disrupting all queues. A single crafted Print-Job request can trigger the crash when the client can reach the scheduler and submit jobs to an accepting, enabled queue supporting the submitted document format. Anonymous submission is possible when permitted by listener and access-control configuration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
OpenPrinting CUPSto a version that resolves this vulnerability.Fixed in 2.4.20
Event History
Frequently Asked Questions
Who can exploit this vulnerability?
An attacker must be able to reach the CUPS scheduler and submit a Print-Job request to an accepting, enabled queue that supports the submitted document format. Anonymous users may be able to exploit it where the listener and access-control configuration permits anonymous job submission.
What is the operational impact of a successful attack?
A single crafted Print-Job request can terminate cupsd. This disrupts all queues on the affected CUPS instance.
Are default CUPS deployments necessarily exposed?
Exposure depends on whether a client can reach the scheduler and submit jobs to an accepting, enabled queue. Anonymous exposure specifically depends on the listener and access-control configuration.
What configuration conditions should be checked while patching is pending?
Check which clients can reach the CUPS scheduler, which queues accept jobs and are enabled, and whether those queues support submitted document formats. Also review listener and access-control settings to determine whether anonymous job submission is allowed.