Infinite loop in libcupsfilters - CVE-2026-64611
Published: July 24, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an infinite loop in cfIEEE1284NormalizeMakeModel when processing an IEEE-1284 device ID with an empty MDL field. A remote attacker can advertise or inject a crafted device ID to cause a denial of service.
Network delivery is possible through printer discovery via IPP or DNS-SD, and the affected consumer can hang on one CPU core indefinitely.