NULL Pointer Dereference in OpenPrinting CUPS Affects Job Scheduling
CVE-2026-107888

5.1MEDIUM

Key Information:

Status
Vendor
CVE Published:
9 October 2026

What is CVE-2026-107888?

OpenPrinting's CUPS, prior to version 2.4.20, is prone to a NULL pointer dereference vulnerability in the cupsdCheckJobs() function. This issue arises when a job that is marked as 'job-held-on-create' refers to a temporary printer that has already been deleted. As the cleanup of temporary printers occurs, the destination can be removed without canceling jobs that are still held, leading to the scheduler attempting to dereference a NULL result from cupsdFindDest(). This situation can cause the cupsd process to terminate unexpectedly, disrupting all job queues it manages. An unprivileged user can exploit this scenario in certain conditions, triggering system interruptions.

Affected Version(s)

CUPS 0 < 2.4.20

References

CVSS V3.1

Score:
5.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.