Heap Out-of-Bounds Read in CUPS Affected by SNMP Parsing
CVE-2026-87875
4.3MEDIUM
What is CVE-2026-87875?
The cupsUTF32ToUTF8() function in CUPS's source file, cups/transcode.c, is susceptible to a vulnerability that stems from a lack of proper source-length bounding. This flaw can lead to heap out-of-bounds reads, enabling attackers to exploit the vulnerability through specially crafted content parsed during SNMP supply-description operations in backend/snmp-supplies.c. This security issue may result in exposing sensitive data or creating instability in the affected CUPS service.
References
CVSS V3.1
Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Red Hat would like to thank pant0m (Independent Security Researcher) for reporting this issue.