Uncaught Exception in libcupsfilters - CVE-2026-64612

 

Uncaught Exception in libcupsfilters - CVE-2026-64612

Published: July 24, 2026


Vulnerability identifier: #VU139341
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-64612
CWE-ID: CWE-248
Exploitation vector: Adjecent network
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to an uncaught exception in the _cfImageReadPNG function when processing a malformed PNG in a print job. A remote attacker can submit a specially crafted print job containing a malformed PNG to cause a denial of service.

The issue causes the imagetoraster or imagetopdf CUPS filter process to terminate with SIGABRT, killing the in-flight print job.


Affected software

libcupsfilters
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Basesystem Module
openEuler
Fedora
cups-filters-cups-browsed-debuginfo
cups-filters-ghostscript
cups-filters-ghostscript-debuginfo
cups-filters-foomatic-rip-debuginfo
cups-filters
cups-filters-cups-browsed
cups-filters-foomatic-rip
cups-filters-debuginfo
cups-filters-debugsource
cups-filters (Red Hat package)
cups-filters-doc
cups-filters-libs
cups-filters-devel
cups-filters-help
libcupsfilters (Red Hat package)
libcupsfilters

How to mitigate CVE-2026-64612

Install security update from vendor's website.

libcupsfilters - update to 2.1.2
cups-filters-cups-browsed-debuginfo - update to 1.0.58-19.38.1
cups-filters-ghostscript - update to 1.0.58-19.38.1
cups-filters-ghostscript-debuginfo - update to 1.0.58-19.38.1
cups-filters-foomatic-rip-debuginfo - update to 1.0.58-19.38.1
cups-filters - addressed in versions 1.0.58-19.38.1, 1.25.0-150200.3.31.1
cups-filters-cups-browsed - update to 1.0.58-19.38.1
cups-filters-foomatic-rip - update to 1.0.58-19.38.1
cups-filters-debuginfo - addressed in versions 1.0.58-19.38.1, 1.25.0-150200.3.31.1
cups-filters-debugsource - addressed in versions 1.0.58-19.38.1, 1.25.0-150200.3.31.1
cups-filters (Red Hat package) - update to 1.20.0-36.el8_10.1
cups-filters-doc - update to 1.20.0-36.0.1
cups-filters-libs - update to 1.20.0-36.0.1
cups-filters-devel - update to 1.20.0-36.0.1
cups-filters - update to 1.20.0-36.0.1
cups-filters-devel - update to 1.25.0-150200.3.31.1
cups-filters-help - update to 1.28.15-7
cups-filters-devel - update to 1.28.15-7
cups-filters-debugsource - update to 1.28.15-7
cups-filters-debuginfo - update to 1.28.15-7
cups-filters - update to 1.28.15-7
libcupsfilters (Red Hat package) - update to 2.0.0-13.el10_2
libcupsfilters - addressed in versions 2.1.1-9.fc43, 2.1.1-9.fc44, 2.1.1-9.fc45, 2.2.0-1.fc45, 2.2.1-1.fc45, 2.2.1-1.fc46

External References

Related Security Bulletins