Sceawere
Vulnerability Detail
CVE-2026-107888UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
CUPS cupsd NULL Pointer Dereference
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 5.1
- Creation Date
- 5h ago
- Vendor
- OpenPrinting
- Product
- CUPS
- Attack Type
- CWE-476: NULL Pointer Dereference
- Vector String
- CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create refers to a temporary printer that has been automatically deleted. Temporary-printer cleanup can remove the destination without canceling its held jobs, and the scheduler dereferences the NULL result of cupsdFindDest() while checking holding_new_jobs. This terminates cupsd and interrupts all queues managed by that process. In some plausible scenarios, an unprivileged submission can trigger this.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "5.1",
"pubDate": "2026-10-09T05:16:44.407Z",
"pubdate": "2026-10-09T05:16:44.407Z",
"executiveSummary": "OpenPrinting CUPS versions prior to 2.4.20 are susceptible to a NULL pointer dereference vulnerability within the cupsdCheckJobs() function.\nThe vulnerability arises from an improper handling of held print jobs associated with temporary printers that have been purged from the system configuration.\nWhen the scheduler attempts to validate jobs marked 'job-held-on-create' against a destination that no longer exists, it fails to perform a pointer existence check before accessing the returned object.\nSuccessful exploitation results in an immediate crash of the cupsd service, leading to a denial-of-service (DoS) condition for all print queues managed by the affected process.\nThe vulnerability can be triggered by an unprivileged user submitting a specifically crafted print job, provided they can interact with the printer daemon.\nThis represents a significant availability risk in multi-user environments where CUPS manages shared printing infrastructure.\nNo authentication is strictly required to initiate the attack flow, as the scheduler's background processing of job states can be influenced by standard print submission requests.",
"technicalDetails": "The core of the vulnerability lies in the logic within cupsdCheckJobs() during the scheduler's internal housekeeping routines. The CUPS scheduler (cupsd) maintains job queues and periodically iterates through these jobs to determine their readiness for processing.\nWhen a job is assigned the status 'job-held-on-create', it remains in the queue waiting for further interaction or specific criteria to be met. If the print job is directed at a 'temporary printer'—a printer dynamically created for a session or task—the scheduler relies on the existence of that destination to manage the job's lifecycle.\nA race condition or logic flaw occurs during the temporary printer cleanup process. If the scheduler removes the temporary printer destination from the internal configuration structures but fails to explicitly cancel or invalidate the associated 'job-held-on-create' jobs, these orphaned jobs continue to exist in a pending state pointing to a non-existent destination.\nWhen cupsdCheckJobs() is invoked, it attempts to locate the destination for these held jobs by calling cupsdFindDest(). Because the printer has been deleted, cupsdFindDest() returns a NULL pointer. The subsequent logic fails to validate the return value of this function before attempting to access members of the resulting structure, specifically while checking the 'holding_new_jobs' flag.\nThe attempt to dereference this NULL pointer triggers a segmentation fault within the cupsd process. Because cupsd is typically a long-running system daemon, this crash causes the immediate termination of the service.\nThe attack flow follows a predictable sequence: First, the attacker initiates a print request directed at a temporary printer instance. Second, the attacker ensures the job enters a 'job-held-on-create' state, often by manipulating job attributes or resource availability. Third, the attacker triggers the cleanup of the temporary printer, potentially by terminating the session or requesting a purge. Fourth, the scheduler's internal job check loop is triggered, leading to the execution of the flawed code path in cupsdCheckJobs().\nBecause the scheduler handles all print queues globally, the crash disrupts not only the attacker's print job but all active print operations across the system, effectively stalling the spooling infrastructure until the service is manually restarted or recovered by the init system. This vulnerability does not require administrative privileges, as the basic interaction with the CUPS daemon via the IPP protocol allows for the submission of print jobs that can be held by the scheduler."
}