Improper input validation in cups - CVE-2026-34980
Published: April 2, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to improper input validation in CUPS PostScript queue processing when handling Print-Job requests with crafted page-border attributes. A remote attacker can send a specially crafted Print-Job request containing a newline-injected page-border value to cause a PPD configuration injection, leading to arbitrary filter execution as the lp user.
The affected system must have a shared PostScript queue enabled and be exposed to the network. The attacker does not require authentication or prior privileges.
Affected software
SUSE Linux Enterprise Server 12 SP5
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise High Performance Computing 12
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
SUSE Linux Micro
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Anolis OS
Basesystem Module
Desktop Applications Module
Development Tools Module
Ubuntu
openEuler
cups-libs-32bit
cups-libs-debuginfo-32bit
cups-debugsource
cups-debuginfo
cups-libs
cups-devel
cups-libs-debuginfo
cups-client-debuginfo
cups
cups-client
cups (Ubuntu package)
cups (Red Hat package)
cups-ipptool
cups-lpd
cups-doc
cups-filesystem
libcupscgi1-debuginfo
libcupsmime1-debuginfo
libcupsppdc1
libcupsimage2
libcupscgi1
cups-config
libcups2-debuginfo
libcupsmime1
libcups2
libcupsimage2-debuginfo
libcupsppdc1-debuginfo
cups-ddk-debuginfo
libcups2-32bit-debuginfo
libcups2-32bit
cups-ddk
cups-printerapp
cups-help
How to mitigate CVE-2026-34980
cups-libs-debuginfo-32bit - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1
cups-debugsource - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1, 2.2.7-150000.3.93.1, 2.4.19-1.1
cups-debuginfo - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1, 2.2.7-150000.3.93.1
cups-libs - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1
cups-devel - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1, 2.2.7-150000.3.93.1
cups-libs-debuginfo - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1
cups-client-debuginfo - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1, 2.2.7-150000.3.93.1
cups - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1, 2.2.7-150000.3.93.1
cups-client - addressed in versions 1.7.5-20.62.1, 1.7.5-20.67.1, 2.2.7-150000.3.93.1
cups (Ubuntu package) - addressed in versions 2.1.3-4ubuntu0.11+esm13, 2.4.1op1-1ubuntu4.20, 2.4.1op1-1ubuntu4.21, 2.4.7-1.2ubuntu7.13, 2.4.7-1.2ubuntu7.14, 2.4.12-0ubuntu3.9, 2.4.12-0ubuntu3.10, 2.4.16-1ubuntu1.2, 2.4.16-1ubuntu1.3
cups (Red Hat package) - update to 2.2.6-68.el8_10
cups - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-client - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-devel - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-ipptool - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-libs - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-lpd - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-doc - addressed in versions 2.2.6-68.0.1, 2.4.10-8
cups-filesystem - addressed in versions 2.2.6-68.0.1, 2.4.10-8
libcupscgi1-debuginfo - update to 2.2.7-150000.3.93.1
libcupsmime1-debuginfo - update to 2.2.7-150000.3.93.1
libcupsppdc1 - update to 2.2.7-150000.3.93.1
libcupsimage2 - update to 2.2.7-150000.3.93.1
libcupscgi1 - update to 2.2.7-150000.3.93.1
cups-config - addressed in versions 2.2.7-150000.3.93.1, 2.4.19-1.1
libcups2-debuginfo - addressed in versions 2.2.7-150000.3.93.1, 2.4.19-1.1
libcupsmime1 - update to 2.2.7-150000.3.93.1
libcups2 - addressed in versions 2.2.7-150000.3.93.1, 2.4.19-1.1
libcupsimage2-debuginfo - update to 2.2.7-150000.3.93.1
libcupsppdc1-debuginfo - update to 2.2.7-150000.3.93.1
cups-ddk-debuginfo - update to 2.2.7-150000.3.93.1
libcups2-32bit-debuginfo - update to 2.2.7-150000.3.93.1
libcups2-32bit - update to 2.2.7-150000.3.93.1
cups-ddk - update to 2.2.7-150000.3.93.1
cups - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-client - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-debuginfo - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-debugsource - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-devel - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-ipptool - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-libs - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-lpd - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-printerapp - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-filesystem - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-help - addressed in versions 2.4.0-19, 2.4.7-13, 2.4.7-14
cups-printerapp - update to 2.4.10-8
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenPrinting cups
- openEuler 24.03 LTS SP3 update for cups
- openEuler 24.03 LTS SP2 update for cups
- SUSE update for cups
- openEuler 22.03 LTS SP4 update for cups
- Anolis OS update for cups
- SUSE update for cups
- Ubuntu update for cups
- Ubuntu update for cups
- SUSE update for cups
- SUSE update for cups
- Red Hat Enterprise Linux 8 update for cups
- Anolis OS update for cups
- Ubuntu update for cups