logo

CUPS: A Critical 9.9 Linux Vulnerability Reviewed

ID: 42363213-0263-5892-9ac1-31cf9e395dcc

STIX ID: report--42363213-0263-5892-9ac1-31cf9e395dcc

Feed Name: Aqua Security Blog

Threat Score
55/100

Date Published: 2024-09-27

Date Updated: 2026-04-26

...
...

Aqua Security analyzed recently disclosed CUPS vulnerabilities (CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, CVE-2024-47177) that can allow remote arbitrary code execution by provisioning a malicious IPP printer and leveraging flaws in cups-browsed, libcupsfilters, libppd, and cups-filters. The advisory explains exploitation preconditions (cups-browsed enabled, UDP/631 reachable, attacker-advertised IPP server, victim-initiated print), references published PoCs, provides detection commands and immediate mitigations (stop/disable cups-browsed, block UDP 631), and recommends patching when available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.