Resource exhaustion in cups - CVE-2025-58436
Published: November 27, 2025
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources when handling delays. A local user can send slow messages to cupsd with a delay of 1 byte per second, causing the daemon to consume excessive resources.
Affected software
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Micro
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Basesystem Module
Desktop Applications Module
Development Tools Module
openSUSE Leap
Ubuntu
openEuler
cups (Ubuntu package)
cups (Red Hat package)
cups-filesystem
cups
cups-client
cups-devel
cups-ipptool
cups-libs
cups-lpd
cups-doc
cups-client-debuginfo
cups-debugsource
libcupsppdc1-32bit
libcupsimage2-32bit-debuginfo
libcups2-32bit
libcupsmime1-32bit-debuginfo
libcupsmime1-32bit
libcups2-32bit-debuginfo
libcupscgi1-32bit-debuginfo
libcupsimage2-32bit
libcupsppdc1-32bit-debuginfo
cups-ddk-debuginfo
libcups2
libcupsimage2
libcupsimage2-debuginfo
libcupsmime1-debuginfo
libcupsppdc1
cups-debuginfo
libcups2-debuginfo
libcupsppdc1-debuginfo
cups-config
libcupsmime1
libcupscgi1-debuginfo
cups-ddk
cups-devel-32bit
libcupscgi1-32bit
libcupscgi1
cups-help
cups-printerapp
How to mitigate CVE-2025-58436
cups (Ubuntu package) - addressed in versions 2.1.3-4ubuntu0.11+esm12, 2.2.7-1ubuntu2.10+esm10, 2.3.1-9ubuntu1.9+esm4, 2.4.1op1-1ubuntu4.16, 2.4.7-1.2ubuntu7.9, 2.4.12-0ubuntu1.6, 2.4.12-0ubuntu3.5
cups (Red Hat package) - addressed in versions 2.2.6-66.el8_10, 2.4.10-12.el10_1.2
cups-filesystem - addressed in versions 2.2.6-66.0.1, 2.4.10-3, 2.4.10-5
cups - addressed in versions 2.2.6-66.0.1, 2.4.10-3, 2.4.10-5
cups-client - addressed in versions 2.2.6-66.0.1, 2.4.10-3, 2.4.10-5
cups-devel - addressed in versions 2.2.6-66.0.1, 2.4.10-3, 2.4.10-5
cups-ipptool - addressed in versions 2.2.6-66.0.1, 2.4.10-3, 2.4.10-5
cups-libs - addressed in versions 2.2.6-66.0.1, 2.4.10-3, 2.4.10-5
cups-lpd - addressed in versions 2.2.6-66.0.1, 2.4.10-3, 2.4.10-5
cups-doc - addressed in versions 2.2.6-66.0.1, 2.4.10-3, 2.4.10-5
cups-client-debuginfo - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
cups-debugsource - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1, 2.4.16-1.1, 2.4.16-160000.1.1
libcupsppdc1-32bit - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcupsimage2-32bit-debuginfo - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcups2-32bit - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcupsmime1-32bit-debuginfo - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcupsmime1-32bit - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcups2-32bit-debuginfo - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcupscgi1-32bit-debuginfo - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcupsimage2-32bit - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcupsppdc1-32bit-debuginfo - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
cups-ddk-debuginfo - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcups2 - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1, 2.4.16-1.1, 2.4.16-160000.1.1
libcupsimage2 - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcupsimage2-debuginfo - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcupsmime1-debuginfo - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcupsppdc1 - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
cups-debuginfo - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1, 2.4.16-160000.1.1
cups-devel - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcups2-debuginfo - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1, 2.4.16-1.1, 2.4.16-160000.1.1
libcupsppdc1-debuginfo - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
cups-config - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1, 2.4.16-1.1, 2.4.16-160000.1.1
cups-client - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcupsmime1 - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
cups - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcupscgi1-debuginfo - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
cups-ddk - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
cups-devel-32bit - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcupscgi1-32bit - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
libcupscgi1 - addressed in versions 2.2.7-150000.3.77.1, 2.2.7-150000.3.80.1, 2.2.7-150000.3.83.1
cups-debugsource - addressed in versions 2.2.13-23, 2.4.0-18, 2.4.7-11
cups - addressed in versions 2.2.13-23, 2.4.0-18, 2.4.7-11
cups-debuginfo - addressed in versions 2.2.13-23, 2.4.0-18, 2.4.7-11
cups-devel - addressed in versions 2.2.13-23, 2.4.0-18, 2.4.7-11
cups-libs - addressed in versions 2.2.13-23, 2.4.0-18, 2.4.7-11
cups-help - addressed in versions 2.2.13-23, 2.4.0-18, 2.4.7-11
cups-filesystem - addressed in versions 2.4.0-18, 2.4.7-11
cups-printerapp - addressed in versions 2.4.0-18, 2.4.7-11
cups-lpd - addressed in versions 2.4.0-18, 2.4.7-11
cups-ipptool - addressed in versions 2.4.0-18, 2.4.7-11
cups-client - addressed in versions 2.4.0-18, 2.4.7-11
cups-printerapp - addressed in versions 2.4.10-3, 2.4.10-5
External References
Related Security Bulletins
- Local denial of service in OpenPrinting CUPS
- SUSE update for cups
- SUSE update for cups
- Ubuntu update for cups
- Ubuntu update for cups
- SUSE update for cups
- Anolis OS update for cups
- Red Hat Enterprise Linux 10 update for cups
- Red Hat Enterprise Linux 8 update for cups
- Anolis OS update for cups
- openEuler 22.03 LTS SP3 update for cups
- openEuler 20.03 LTS SP4 update for cups
- openEuler 24.03 LTS SP2 update for cups
- openEuler 24.03 LTS SP1 update for cups
- openEuler 24.03 LTS update for cups
- openEuler 22.03 LTS SP4 update for cups
- SUSE update for cups
- SUSE update for cups
- Anolis OS update for cups