logo

CUPS Vulnerabilities Could Allow Remote Attackers to Achieve Root-Level Code Execution

ID: da04eb66-60f5-5ec3-ab57-84e8540e48aa

STIX ID: report--da04eb66-60f5-5ec3-ab57-84e8540e48aa

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-04-07

Date Updated: 2026-04-22

Author: Divya

...
...

Two critical vulnerabilities in the CUPS printing system were disclosed: CVE-2026-34980 enables unauthenticated remote code execution by injecting newline-smuggled configuration into shared PostScript queues to run arbitrary print filters, and CVE-2026-34990 allows a low-privileged local user to race a validation flow, obtain elevated privileges, and overwrite root-owned files by creating and sharing temporary printer queues; public fixes exist in commits but no formal release yet, and mitigations include disabling network exposure, enforcing authentication, and using AppArmor/SELinux containment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.