NULL Pointer Dereference in OpenPrinting CUPS Affects Job Scheduling
CVE-2026-107888
5.1MEDIUM
What is CVE-2026-107888?
OpenPrinting's CUPS, prior to version 2.4.20, is prone to a NULL pointer dereference vulnerability in the cupsdCheckJobs() function. This issue arises when a job that is marked as 'job-held-on-create' refers to a temporary printer that has already been deleted. As the cleanup of temporary printers occurs, the destination can be removed without canceling jobs that are still held, leading to the scheduler attempting to dereference a NULL result from cupsdFindDest(). This situation can cause the cupsd process to terminate unexpectedly, disrupting all job queues it manages. An unprivileged user can exploit this scenario in certain conditions, triggering system interruptions.
Affected Version(s)
CUPS 0 < 2.4.20
