#VU118817 Out-of-bounds write in cups - CVE-2025-61915
Published: November 27, 2025
cups
OpenPrinting
Description
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input when parsing IPv6 address within the get_addr_and_mask() function. A local user in the lpadmin group can use the cups web UI to change the configuration and crash the daemon.