Uncaught Exception in libcupsfilters - CVE-2026-64612
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an uncaught exception in the _cfImageReadPNG function when processing a malformed PNG in a print job. A remote attacker can submit a specially crafted print job containing a malformed PNG to cause a denial of service.
The issue causes the imagetoraster or imagetopdf CUPS filter process to terminate with SIGABRT, killing the in-flight print job.
Affected software
SUSE Linux Enterprise Server 12 SP5 LTSS Extended
SUSE Linux Enterprise Server for SAP Applications 12
SUSE Linux Enterprise Server 12
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
Red Hat Enterprise Linux for IBM z Systems
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for x86_64
Basesystem Module
openEuler
Fedora
cups-filters-cups-browsed-debuginfo
cups-filters-ghostscript
cups-filters-ghostscript-debuginfo
cups-filters-foomatic-rip-debuginfo
cups-filters
cups-filters-cups-browsed
cups-filters-foomatic-rip
cups-filters-debuginfo
cups-filters-debugsource
cups-filters (Red Hat package)
cups-filters-doc
cups-filters-libs
cups-filters-devel
cups-filters-help
libcupsfilters (Red Hat package)
libcupsfilters
How to mitigate CVE-2026-64612
cups-filters-cups-browsed-debuginfo - update to 1.0.58-19.38.1
cups-filters-ghostscript - update to 1.0.58-19.38.1
cups-filters-ghostscript-debuginfo - update to 1.0.58-19.38.1
cups-filters-foomatic-rip-debuginfo - update to 1.0.58-19.38.1
cups-filters - addressed in versions 1.0.58-19.38.1, 1.25.0-150200.3.31.1
cups-filters-cups-browsed - update to 1.0.58-19.38.1
cups-filters-foomatic-rip - update to 1.0.58-19.38.1
cups-filters-debuginfo - addressed in versions 1.0.58-19.38.1, 1.25.0-150200.3.31.1
cups-filters-debugsource - addressed in versions 1.0.58-19.38.1, 1.25.0-150200.3.31.1
cups-filters (Red Hat package) - update to 1.20.0-36.el8_10.1
cups-filters-doc - update to 1.20.0-36.0.1
cups-filters-libs - update to 1.20.0-36.0.1
cups-filters-devel - update to 1.20.0-36.0.1
cups-filters - update to 1.20.0-36.0.1
cups-filters-devel - update to 1.25.0-150200.3.31.1
cups-filters-help - update to 1.28.15-7
cups-filters-devel - update to 1.28.15-7
cups-filters-debugsource - update to 1.28.15-7
cups-filters-debuginfo - update to 1.28.15-7
cups-filters - update to 1.28.15-7
libcupsfilters (Red Hat package) - update to 2.0.0-13.el10_2
libcupsfilters - addressed in versions 2.1.1-9.fc43, 2.1.1-9.fc44, 2.1.1-9.fc45, 2.2.0-1.fc45, 2.2.1-1.fc45, 2.2.1-1.fc46
External References
Related Security Bulletins
- Multiple vulnerabilities in OpenPrinting cups-filters and libcupsfilters
- Fedora 43 update for libcupsfilters
- openEuler update for cups-filters
- Fedora 45 update for libcupsfilters
- Fedora 44 update for libcupsfilters
- Fedora 45 update for libcupsfilters
- Fedora 46 update for libcupsfilters
- Fedora 45 update for libcupsfilters
- Red Hat Enterprise Linux 10 update for libcupsfilters
- Red Hat Enterprise Linux 8 update for cups-filters
- SUSE update for cups-filters
- SUSE update for cups-filters
- Anolis OS update for cups-filters