CUPS Vulnerabilities Could Allow Remote Attackers to Achieve Root-Level Code Execution
ID: da04eb66-60f5-5ec3-ab57-84e8540e48aa
STIX ID: report--da04eb66-60f5-5ec3-ab57-84e8540e48aa
Feed Name: GBHackers
Two critical vulnerabilities in the CUPS printing system were disclosed: CVE-2026-34980 enables unauthenticated remote code execution by injecting newline-smuggled configuration into shared PostScript queues to run arbitrary print filters, and CVE-2026-34990 allows a low-privileged local user to race a validation flow, obtain elevated privileges, and overwrite root-owned files by creating and sharing temporary printer queues; public fixes exist in commits but no formal release yet, and mitigations include disabling network exposure, enforcing authentication, and using AppArmor/SELinux containment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
