logo

Small praise for modern compilers - A case of Ubuntu printing vulnerability that wasn’t

ID: 9feecf16-7af8-5f65-a95e-a8d4e0eb7962

STIX ID: report--9feecf16-7af8-5f65-a95e-a8d4e0eb7962

Feed Name: Cisco Talos

Threat Score
20/100

Date Published: 2025-02-10

Date Updated: 2026-04-27

Author: Aleksandar Nikolic

...
...

The report details discovery and exploitation of a buffer-overflow bug in the deprecated ippusbxd IPP-over-USB daemon on Ubuntu 22.04. The author builds a PoC by emulating a malicious USB printer (using PAPPL and a Raspberry Pi Zero) that reports an oversized media-size value, triggering a segfault in ippusbxd; however, compiler mitigations (FORTIFY_SOURCE and -Wstringop-overflow) cause a detected abort rather than reliable code execution, and ippusbxd has been superseded by the memory-safe ipp-usb implementation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.