#VU125822 Integer underflow in cups - CVE-2026-39314
Published: April 11, 2026 / Updated: April 17, 2026
cups
OpenPrinting
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to integer underflow in _ppdCreateFromIPP() in cups/ppd-cache.c when processing a negative job-password-supported IPP attribute. A local user can supply a crafted IPP response to cause a denial of service.
Exploitation involves creating a local printer that points to a fake IPP printer on localhost, causing the cupsd root process to crash.