REDHAT-BUG-2393078: Null Pointer Dereference

Published Sep 4, 2025
·
Updated

Null Pointer Dereference vulnerability in the ippreadio() function of the CUPS printing system. The flaw is caused by unsafe deserialization and improper validation of crafted printer attribute responses. When ippValidateAttributes() processes such responses, a null pointer dereference occurs, leading to application crash. This issue can be exploited remotely within the local subnet in default configurations, and in some cases over the network if IPP services are exposed. Exploitation requires no authentication or user interaction, allowing attackers to disrupt availability of printing services on affected systems.

Affected Software

1 affected component
Apple CUPS

Event History

Sep 4, 2025
Data Sourced
via Red Hat·09:57 AM
DescriptionSeverityAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2393078?

The severity of REDHAT-BUG-2393078 is considered high due to the potential for a null pointer dereference that can lead to application crashes.

2

How do I fix REDHAT-BUG-2393078?

To fix REDHAT-BUG-2393078, update your CUPS system to the latest version that addresses the vulnerability.

3

What is the impact of REDHAT-BUG-2393078?

The impact of REDHAT-BUG-2393078 includes potential denial of service due to crashes when handling malicious printer attribute responses.

4

Who is affected by REDHAT-BUG-2393078?

Users of Apple CUPS are notably affected by the REDHAT-BUG-2393078 vulnerability.

5

Is there a workaround for REDHAT-BUG-2393078?

There are no recommended workarounds for REDHAT-BUG-2393078; applying the latest updates is the best mitigation strategy.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203