Resource Exhaustion Vulnerability in OpenPrinting CUPS Affected by Client Connection Issues
CVE-2026-107885
What is CVE-2026-107885?
OpenPrinting's CUPS version 2.4.20 is susceptible to a resource exhaustion vulnerability that arises during the submission-timeout handling of cupsdCheckJobs(). The issue occurs when the print scheduler fails to process timeouts for all pending jobs if there is an active Send-Document operation from any client. This can lead to scenarios where clients exploiting the IPP service can hold incomplete HTTP requests with parsed Send-Document headers, preventing necessary job expirations. As these incomplete jobs accumulate, the maximum job limit can be reached, effectively blocking further legitimate print submissions. Only when the associated client connection is closed does the issue resolve, allowing previously stuck jobs to be processed again.
Affected Version(s)
CUPS 0 <= 2.4.20
