NULL Pointer Dereference in OpenPrinting CUPS Affects Multiple Versions
CVE-2026-107890
3.3LOW
What is CVE-2026-107890?
OpenPrinting CUPS, prior to version 2.4.20, is susceptible to a NULL pointer dereference vulnerability triggered by malformed IPP job-creation requests. This issue arises when repeated IPP group tags result in unnamed separator attributes that disrupt the job creation process. The flawed handling of these attributes allows a crafted Print-Job request to call strlen() on a NULL attribute, leading to a crash of the cupsd service and potentially halting all job queues. The vulnerability can be exploited by an attacker capable of submitting jobs to a vulnerable CUPS server, particularly if anonymous job submission is enabled in the server's configuration.
Affected Version(s)
CUPS 0 < 2.4.20
