CVE-2026-41079
Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer.
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
- EPSS
- 0.41% probability · 34th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125, CWE-200
- Affected
- openprinting/cups
- Source
- security-advisories@github.com
References
- https://github.com/OpenPrinting/cups/commit/b7c2525a885f528d243c3a92197ca99609b3f080Patch
- https://github.com/OpenPrinting/cups/commit/d7fe0f521ff3b24676511e747b058362b9a20737Patch
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-6wpw-g8g6-wvrvExploit, Mitigation, Patch, Vendor Advisory
- https://github.com/OpenPrinting/cups/security/advisories/GHSA-6wpw-g8g6-wvrvExploit, Mitigation, Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.