Sceawere

Vulnerability Detail

CVE-2026-107885UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CUPS cupsdCheckJobs Resource Exhaustion

Vulnerability Metadata

Severity
Low
Score / CVSS
3.3
Creation Date
3h ago
Vendor
OpenPrinting
Product
CUPS
Attack Type
CWE-770 Allocation of Resources Without Limits or Throttling
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

OpenPrinting CUPS through 2.4.20 contains a resource-exhaustion vulnerability in the submission-timeout handling of cupsdCheckJobs(). The scheduler suppresses timeout processing for all pending jobs whenever any client connection has an in-flight Send-Document operation, without matching that connection to the job being examined. A client allowed to reach the IPP service can hold an incomplete HTTP request containing parsed Send-Document headers before operation authorization, preventing unrelated incomplete jobs from expiring. Where Create-Job submission is allowed, incomplete jobs can accumulate until MaxJobs is exhausted and further legitimate print submissions are rejected. The suppression ends when the held connection closes.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.3",
  "pubDate": "2026-10-09T04:18:04.940Z",
  "pubdate": "2026-10-09T04:18:04.940Z",
  "executiveSummary": "OpenPrinting CUPS versions through 2.4.20 are susceptible to a resource-exhaustion vulnerability within the cupsdCheckJobs() function.\nThe vulnerability stems from improper handling of submission-timeout processing, specifically during in-flight Send-Document operations.\nAn unauthenticated attacker with network access to the IPP service can intentionally stall the job-cleanup process by maintaining an incomplete HTTP request.\nThis logic flaw results in the suppression of timeout processing for all pending jobs, effectively preventing the scheduler from expiring stale or incomplete print requests.\nBy continuously exploiting this mechanism, an attacker can cause an accumulation of incomplete jobs until the configured MaxJobs limit is reached.\nOnce the MaxJobs threshold is exhausted, the scheduler will reject all subsequent legitimate print submissions, leading to a Denial of Service (DoS) for the printing subsystem.\nThe attack requires only the ability to reach the IPP service and does not necessitate prior authentication, making the service vulnerable to remote exploitation.",
  "technicalDetails": "The vulnerability is located within the CUPS scheduler's job monitoring logic, specifically in the implementation of cupsdCheckJobs().\nIn the affected versions, the scheduler incorrectly suppresses timeout processing for all pending jobs whenever any active client connection has an in-flight Send-Document IPP operation.\nThe failure occurs because the scheduler performs a global suppression check without verifying whether the specific connection triggering the Send-Document state corresponds to the job currently being evaluated for timeout.\nThe attack flow begins when a malicious client establishes an IPP connection and submits an incomplete HTTP request containing parsed Send-Document headers. The client purposefully leaves the request incomplete, keeping the connection open and the state in an 'in-flight' status.\nBecause cupsdCheckJobs() evaluates the state of the scheduler globally, the presence of this stalled request signals the scheduler to pause all timeout-related housecleaning.\nDuring this period, any other jobs that would normally be terminated due to submission timeouts are instead retained in the system's memory and state database.\nAn attacker can repeat this process or maintain the connection to ensure that the MaxJobs threshold is reached. MaxJobs is a critical configuration parameter that limits the total number of simultaneous print jobs the scheduler will track.\nOnce the scheduler reaches this limit, it enters a state where it can no longer accept new print requests, effectively denying service to all legitimate users of the CUPS instance.\nThe suppression mechanism remains active as long as the malicious client keeps the connection open. Upon the closure of the held connection, the timeout logic resumes, but the prior accumulation of stale jobs persists until cleared manually or through delayed processing, assuming the system has not already reached a fatal state of exhaustion.\nThis vulnerability highlights a flaw in the serialization of task-specific state validation within the IPP stack. The dependency on a broad, connection-agnostic state check allows remote, unauthenticated actors to exert influence over the scheduler's garbage collection cycles, transforming a benign timeout management function into a reliable vector for resource exhaustion."
}
CVE-2026-107885: CUPS cupsdCheckJobs Resource Exhaustion (LOW Severity, CVSS: 3.3) | Sceawere