Heap Out-of-Bounds Read in CUPS Affected by SNMP Parsing
CVE-2026-87875

4.3MEDIUM

What is CVE-2026-87875?

The cupsUTF32ToUTF8() function in CUPS's source file, cups/transcode.c, is susceptible to a vulnerability that stems from a lack of proper source-length bounding. This flaw can lead to heap out-of-bounds reads, enabling attackers to exploit the vulnerability through specially crafted content parsed during SNMP supply-description operations in backend/snmp-supplies.c. This security issue may result in exposing sensitive data or creating instability in the affected CUPS service.

References

CVSS V3.1

Score:
4.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Red Hat would like to thank pant0m (Independent Security Researcher) for reporting this issue.
.