CVE-2025-61915: Buffer Underflow Vulnerability Leads to Memory Corruption in CUPS
ID: a90ce11a-3085-5521-9742-08af287bfb9a
STIX ID: report--a90ce11a-3085-5521-9742-08af287bfb9a
Feed Name: LevelBlue SpiderLabs Blog
Threat Score
CVE-2025-61915 is a critical stack-based out-of-bounds write (pseudo stack underflow) in CUPS' IPv6 parser that can be abused to modify cupsd.conf and achieve local privilege escalation to root — and remote code execution as root where remote administration is enabled. The report provides detailed fuzzing setup, analysis of the vulnerable parser function, debugging notes, gadget finding, and a ROP-chain proof-of-concept delivered via a crafted IPv6 address in cupsd.conf.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
