[ubuntu/resolute-proposed] cups 2.4.16-1ubuntu2 (Accepted)

Marc Deslauriers marc.deslauriers at ubuntu.com
Fri Apr 10 09:45:41 UTC 2026


cups (2.4.16-1ubuntu2) resolute; urgency=medium

  * SECURITY UPDATE: authorization bypass vulnerability
    - debian/patches/CVE-2026-27447.patch: don't treat local user and group
      names as case-insensitive in scheduler/auth.c.
    - CVE-2026-27447
  * SECURITY UPDATE: RSS notifier path traversal issue
    - debian/patches/CVE-2026-34978.patch: fix RSS notifier in
      notifier/rss.c, scheduler/ipp.c.
    - CVE-2026-34978
  * SECURITY UPDATE: heap overflow in building filter option strings
    - debian/patches/CVE-2026-34979-1.patch: expand allocation of options
      string in scheduler/job.c.
    - debian/patches/CVE-2026-34979-2.patch: fix get_options regression in
      scheduler/job.c, test/5.5-lp.sh.
    - CVE-2026-34979
  * SECURITY UPDATE: embedded newline issue in print jobs
    - debian/patches/CVE-2026-34980.patch: filter out control characters
      from option values in scheduler/job.c.
    - CVE-2026-34980
  * SECURITY UPDATE: incorrectly accepts local certificates over the
    loopback interface
    - debian/patches/CVE-2026-34990.patch: don't allow local certificates
      over the loopback interface, drop support for writing to plain files
      in cups/auth.c, scheduler/auth.c, scheduler/client.c,
      scheduler/ipp.c, scheduler/job.c, test/4.2-cups-printer-ops.test,
      test/5.1-lpadmin.sh.
    - CVE-2026-34990
  * SECURITY UPDATE: integer underflow in _ppdCreateFromIPP()
    - debian/patches/CVE-2026-39314.patch: range check
      job-password-supported in cups/ppd-cache.c.
    - CVE-2026-39314
  * SECURITY UPDATE: use-after-free when temp printers are deleted
    - debian/patches/CVE-2026-39316.patch: expire per-printer subscriptions
      before deleting in scheduler/printers.c.
    - CVE-2026-39316
  * SECURITY UPDATE: OOB read in cupsdSetPrinterAttr marker-types parsing
    - debian/patches/cupsdsetprinterattr-oob-read.patch: protect against a
      driver reporting a supply type with a trailing dash in
      scheduler/printers.c.
    - No CVE number

Date: Thu, 09 Apr 2026 10:46:45 -0400
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
https://launchpad.net/ubuntu/+source/cups/2.4.16-1ubuntu2
-------------- next part --------------
Format: 1.8
Date: Thu, 09 Apr 2026 10:46:45 -0400
Source: cups
Built-For-Profiles: derivative.ubuntu noudeb
Architecture: source
Version: 2.4.16-1ubuntu2
Distribution: resolute
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Marc Deslauriers <marc.deslauriers at ubuntu.com>
Changes:
 cups (2.4.16-1ubuntu2) resolute; urgency=medium
 .
   * SECURITY UPDATE: authorization bypass vulnerability
     - debian/patches/CVE-2026-27447.patch: don't treat local user and group
       names as case-insensitive in scheduler/auth.c.
     - CVE-2026-27447
   * SECURITY UPDATE: RSS notifier path traversal issue
     - debian/patches/CVE-2026-34978.patch: fix RSS notifier in
       notifier/rss.c, scheduler/ipp.c.
     - CVE-2026-34978
   * SECURITY UPDATE: heap overflow in building filter option strings
     - debian/patches/CVE-2026-34979-1.patch: expand allocation of options
       string in scheduler/job.c.
     - debian/patches/CVE-2026-34979-2.patch: fix get_options regression in
       scheduler/job.c, test/5.5-lp.sh.
     - CVE-2026-34979
   * SECURITY UPDATE: embedded newline issue in print jobs
     - debian/patches/CVE-2026-34980.patch: filter out control characters
       from option values in scheduler/job.c.
     - CVE-2026-34980
   * SECURITY UPDATE: incorrectly accepts local certificates over the
     loopback interface
     - debian/patches/CVE-2026-34990.patch: don't allow local certificates
       over the loopback interface, drop support for writing to plain files
       in cups/auth.c, scheduler/auth.c, scheduler/client.c,
       scheduler/ipp.c, scheduler/job.c, test/4.2-cups-printer-ops.test,
       test/5.1-lpadmin.sh.
     - CVE-2026-34990
   * SECURITY UPDATE: integer underflow in _ppdCreateFromIPP()
     - debian/patches/CVE-2026-39314.patch: range check
       job-password-supported in cups/ppd-cache.c.
     - CVE-2026-39314
   * SECURITY UPDATE: use-after-free when temp printers are deleted
     - debian/patches/CVE-2026-39316.patch: expire per-printer subscriptions
       before deleting in scheduler/printers.c.
     - CVE-2026-39316
   * SECURITY UPDATE: OOB read in cupsdSetPrinterAttr marker-types parsing
     - debian/patches/cupsdsetprinterattr-oob-read.patch: protect against a
       driver reporting a supply type with a trailing dash in
       scheduler/printers.c.
     - No CVE number
Checksums-Sha1:
 20063758a615669d3ac8d64f9a5d6d7c5a943cc1 3439 cups_2.4.16-1ubuntu2.dsc
 0d9133877306e0edeed5d8bb128d8c9a1974c57f 406632 cups_2.4.16-1ubuntu2.debian.tar.xz
 3bc48ce82f341759f72ee66a07c902881a22d377 11508 cups_2.4.16-1ubuntu2_source.buildinfo
Checksums-Sha256:
 d57d07720da4cddac74e02f55c88676a570a1a9aa77c0bf91d5c6e0961ff6af1 3439 cups_2.4.16-1ubuntu2.dsc
 8c0148bbd25b5e3d70fcdd56b0270745fd4d9ab9957317e8cd199c94b0b1a110 406632 cups_2.4.16-1ubuntu2.debian.tar.xz
 882a128014297a6869c6cbcf43760b804ea3196f12837c36839aa0275a13a870 11508 cups_2.4.16-1ubuntu2_source.buildinfo
Files:
 1332ffaef420b6c00153ee8d79a2d31d 3439 net optional cups_2.4.16-1ubuntu2.dsc
 f93c2c5ae3a6cca2347285449303ab73 406632 net optional cups_2.4.16-1ubuntu2.debian.tar.xz
 f10e969e0fd746d65af98f330c90a17b 11508 net optional cups_2.4.16-1ubuntu2_source.buildinfo
Original-Maintainer: Debian Printing Team <debian-printing at lists.debian.org>


More information about the Resolute-changes mailing list