Double-Free Vulnerability in CUPS Printer Management by OpenPrinting
CVE-2026-107886
2.3LOW
What is CVE-2026-107886?
A double-free vulnerability exists in OpenPrinting's CUPS before version 2.4.20 within printer-class management. When modifying a class member list using CUPS-Add-Modify-Class, the process incorrectly frees a pointer without clearing it, leading to a dangling pointer. If validation fails, this issue allows authorized clients to trigger a denial of service across the CUPS scheduler by invoking CUPS-Delete-Class, which can free the same memory allocation again, disrupting the service completely. The default policy necessitates @SYSTEM privileges to exploit this vulnerability, highlighting a significant risk for systems relying on CUPS for printing services.
Affected Version(s)
CUPS 1.4.8 < 2.4.20
