Improper input validation in cups - CVE-2026-34980

 

Improper input validation in cups - CVE-2026-34980

Published: April 2, 2026


Vulnerability identifier: #VU124813
CSH Severity: High
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-34980
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to improper input validation in CUPS PostScript queue processing when handling Print-Job requests with crafted page-border attributes. A remote attacker can send a specially crafted Print-Job request containing a newline-injected page-border value to cause a PPD configuration injection, leading to arbitrary filter execution as the lp user.

The affected system must have a shared PostScript queue enabled and be exposed to the network. The attacker does not require authentication or prior privileges.


Affected software

cups
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Micro
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Basesystem Module
Desktop Applications Module
Development Tools Module
Ubuntu
openEuler
cups-libs-32bit
cups-libs-debuginfo-32bit
cups-debugsource
cups-debuginfo
cups-libs
cups-devel
cups-libs-debuginfo
cups-client-debuginfo
cups
cups-client
cups (Ubuntu package)
cups (Red Hat package)
cups-ipptool
cups-lpd
cups-doc
cups-filesystem
libcupscgi1-debuginfo
libcupsmime1-debuginfo
libcupsppdc1
libcupsimage2
libcupscgi1
cups-config
libcups2-debuginfo
libcupsmime1
libcups2
libcupsimage2-debuginfo
libcupsppdc1-debuginfo
cups-ddk-debuginfo
libcups2-32bit-debuginfo
libcups2-32bit
cups-ddk
cups-printerapp
cups-help

How to mitigate CVE-2026-34980

Install security update from vendor's website.

cups-libs-32bit - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1
cups-libs-debuginfo-32bit - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1
cups-debugsource - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1, 2.2.7-150000.3.93.1, 2.4.19-1.1
cups-debuginfo - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1, 2.2.7-150000.3.93.1
cups-libs - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1
cups-devel - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1, 2.2.7-150000.3.93.1
cups-libs-debuginfo - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1
cups-client-debuginfo - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1, 2.2.7-150000.3.93.1
cups - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1, 2.2.7-150000.3.93.1
cups-client - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1, 2.2.7-150000.3.93.1
cups (Ubuntu package) - addressed in versions 2.1.3-4ubuntu0.11+esm13, 2.4.1op1-1ubuntu4.20, 2.4.1op1-1ubuntu4.21, 2.4.7-1.2ubuntu7.13, 2.4.7-1.2ubuntu7.14, 2.4.12-0ubuntu3.9, 2.4.12-0ubuntu3.10, 2.4.16-1ubuntu1.2, 2.4.16-1ubuntu1.3
cups (Red Hat package) - update to 2.2.6-68.el8_10
cups - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-client - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-devel - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-ipptool - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-libs - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-lpd - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-doc - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-filesystem - addressed in versions 2.2.6-68.0.1, 2.4.10-8
libcupscgi1-debuginfo - update to 2.2.7-150000.3.93.1
libcupsmime1-debuginfo - update to 2.2.7-150000.3.93.1
libcupsppdc1 - update to 2.2.7-150000.3.93.1
libcupsimage2 - update to 2.2.7-150000.3.93.1
libcupscgi1 - update to 2.2.7-150000.3.93.1
cups-config - addressed in versions 2.2.7-150000.3.93.1, 2.4.19-1.1
libcups2-debuginfo - addressed in versions 2.2.7-150000.3.93.1, 2.4.19-1.1
libcupsmime1 - update to 2.2.7-150000.3.93.1
libcups2 - addressed in versions 2.2.7-150000.3.93.1, 2.4.19-1.1
libcupsimage2-debuginfo - update to 2.2.7-150000.3.93.1
libcupsppdc1-debuginfo - update to 2.2.7-150000.3.93.1
cups-ddk-debuginfo - update to 2.2.7-150000.3.93.1
libcups2-32bit-debuginfo - update to 2.2.7-150000.3.93.1
libcups2-32bit - update to 2.2.7-150000.3.93.1
cups-ddk - update to 2.2.7-150000.3.93.1
cups - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-client - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-debuginfo - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-debugsource - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-devel - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-ipptool - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-libs - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-lpd - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-printerapp - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-filesystem - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-help - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-printerapp - update to 2.4.10-8

External References

Related Security Bulletins