Sceawere

Vulnerability Detail

CVE-2026-107890UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

CUPS IPP NULL Pointer Dereference

Vulnerability Metadata

Severity
Low
Score / CVSS
3.3
Creation Date
5h ago
Vendor
OpenPrinting
Product
CUPS
Attack Type
CWE-476: NULL Pointer Dereference
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L
Attack Complexity
LOW

Narrative and Response

Description

OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference caused by repeated IPP group tags in job-creation requests. IPP parsing creates unnamed separator attributes with IPP_TAG_ZERO, but add_job() converts these separators to IPP_TAG_JOB. During job startup, get_options()/ipp_length() subsequently calls strlen() on a NULL attribute name, terminating cupsd and disrupting all queues. A single crafted Print-Job request can trigger the crash when the client can reach the scheduler and submit jobs to an accepting, enabled queue supporting the submitted document format. Anonymous submission is possible when permitted by listener and access-control configuration.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.3",
  "pubDate": "2026-10-09T05:16:44.730Z",
  "pubdate": "2026-10-09T05:16:44.730Z",
  "executiveSummary": "OpenPrinting CUPS versions prior to 2.4.20 are susceptible to a critical NULL pointer dereference vulnerability within the IPP parsing logic of the cupsd scheduler.\nThe vulnerability occurs during the processing of crafted job-creation requests containing repeated IPP group tags, leading to an unconditional termination of the cupsd process.\nThis flaw facilitates a remote denial-of-service (DoS) condition, effectively disrupting all printing queues managed by the affected scheduler instance.\nExploitation is feasible for any attacker capable of reaching the print scheduler and submitting a job to an enabled queue. Depending on the server's listener and access-control configuration, the vulnerability may be reachable via anonymous submission.\nThe risk is significant due to the simplicity of the attack payload and the high impact on service availability. There are no special privilege requirements beyond the ability to submit a print job, making this an accessible vector for attackers within the network perimeter.",
  "technicalDetails": "The vulnerability resides in the IPP parsing implementation within the OpenPrinting CUPS cupsd component. The root cause is an improper handling of repeated IPP group tags within an IPP job-creation request.\nWhen the scheduler receives a job-creation request, the IPP parser is designed to identify and process attribute groups. During this phase, the parser generates unnamed separator attributes, which are temporarily marked with the IPP_TAG_ZERO tag type.\nSubsequent logic in the add_job() function attempts to normalize these attributes by converting the IPP_TAG_ZERO tags into IPP_TAG_JOB. This conversion process is flawed when presented with a specially crafted, repeated group tag sequence, resulting in an inconsistent state for the attribute structure.\nThe crash is triggered during the job startup phase when the scheduler invokes get_options() or ipp_length(). These functions iterate through the attribute list to calculate buffer lengths or extract job parameters. Because of the previous misconfiguration of the separator attributes, the system encounters an attribute entry with a NULL name pointer.\nThe execution flow continues into a call to strlen() using this NULL pointer as an argument, causing an immediate segmentation fault and the termination of the cupsd daemon.\nThe attack flow follows a structured path: 1) The attacker constructs an IPP packet containing a malformed sequence of repeating IPP group tags; 2) The packet is transmitted to the CUPS scheduler via the IPP protocol; 3) The cupsd parser processes the payload, creating the improperly initialized attribute objects; 4) The add_job() function performs the flawed conversion; 5) The downstream job startup sequence attempts to read the attribute metadata, triggering the dereference of the NULL pointer.\nSince the cupsd process is responsible for managing all printing queues, its unexpected termination results in a complete denial-of-service for the print server. Any user or entity with network access to the scheduler and permissions to submit a job to an active, enabled queue can trigger this crash. If the server is configured to permit anonymous print job submission, the attack can be executed without prior authentication."
}
CVE-2026-107890: CUPS IPP NULL Pointer Dereference (LOW Severity, CVSS: 3.3) | Sceawere