RHSA-2026:57451: Moderate: cups-filters security update
Moderate: cups-filters security update
Other sources
The cups-filters package contains back ends, filters, and other software that was once part of the core Common UNIX Printing System (CUPS) distribution but is now maintained independently. Security Fix(es): libcupsfilters: cups-filters: libcupsfilters: CUPS image filter process abort via malformed PNG (CVE-2026-64612) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.
— Red Hat
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
redhat/cups-filtersto a version that resolves this vulnerability.Fixed in 1.20.0-36.el8_10.1 - Upgrade
Upgrade
redhat/cups-filters-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.0-36.el8_10.1 - Upgrade
Upgrade
redhat/cups-filters-debugsourceto a version that resolves this vulnerability.Fixed in 1.20.0-36.el8_10.1 - Upgrade
Upgrade
redhat/cups-filters-libsto a version that resolves this vulnerability.Fixed in 1.20.0-36.el8_10.1 - Upgrade
Upgrade
redhat/cups-filters-libs-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.0-36.el8_10.1 - Upgrade
Upgrade
redhat/cups-filtersto a version that resolves this vulnerability.Fixed in 1.20.0-36.el8_10.1.aa - Upgrade
Upgrade
redhat/cups-filters-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.0-36.el8_10.1.aa - Upgrade
Upgrade
redhat/cups-filters-debugsourceto a version that resolves this vulnerability.Fixed in 1.20.0-36.el8_10.1.aa - Upgrade
Upgrade
redhat/cups-filters-libsto a version that resolves this vulnerability.Fixed in 1.20.0-36.el8_10.1.aa - Upgrade
Upgrade
redhat/cups-filters-libs-debuginfoto a version that resolves this vulnerability.Fixed in 1.20.0-36.el8_10.1.aa - Upgrade
Upgrade
redhat/cups-filters-develto a version that resolves this vulnerability.Fixed in 1.20.0-36.el8_10.1 - Upgrade
Upgrade
redhat/cups-filters-develto a version that resolves this vulnerability.Fixed in 1.20.0-36.el8_10.1.aa
Event History
Frequently Asked Questions
What must an attacker provide to trigger the issue?
The issue is triggered by a malformed PNG image processed by the libcupsfilters CUPS image filter.
What is the documented impact of successful exploitation?
Processing the malformed PNG can cause the CUPS image filter process to abort.
Which installed packages are relevant when assessing exposure?
Review systems with cups-filters or cups-filters-libs installed. The advisory also lists related debuginfo, debugsource, and development packages.