CVE-2026-107890: Null Pointer Dereference

Published Oct 9, 2026
·
Updated

OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference caused by repeated IPP group tags in job-creation requests. IPP parsing creates unnamed separator attributes with IPPTAGZERO, but addjob() converts these separators to IPPTAGJOB. During job startup, getoptions()/ipplength() subsequently calls strlen() on a NULL attribute name, terminating cupsd and disrupting all queues. A single crafted Print-Job request can trigger the crash when the client can reach the scheduler and submit jobs to an accepting, enabled queue supporting the submitted document format. Anonymous submission is possible when permitted by listener and access-control configuration.

Affected Software

1 affected component
OpenPrinting CUPS<2.4.20

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade OpenPrinting CUPS to a version that resolves this vulnerability.

    Fixed in 2.4.20

Event History

Oct 9, 2026
CVE Published
via MITRE·04:10 AM
Data Sourced
via MITRE·04:10 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this vulnerability?

An attacker must be able to reach the CUPS scheduler and submit a Print-Job request to an accepting, enabled queue that supports the submitted document format. Anonymous users may be able to exploit it where the listener and access-control configuration permits anonymous job submission.

2

What is the operational impact of a successful attack?

A single crafted Print-Job request can terminate cupsd. This disrupts all queues on the affected CUPS instance.

3

Are default CUPS deployments necessarily exposed?

Exposure depends on whether a client can reach the scheduler and submit jobs to an accepting, enabled queue. Anonymous exposure specifically depends on the listener and access-control configuration.

4

What configuration conditions should be checked while patching is pending?

Check which clients can reach the CUPS scheduler, which queues accept jobs and are enabled, and whether those queues support submitted document formats. Also review listener and access-control settings to determine whether anonymous job submission is allowed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203