CVE-2026-34979

MEDIUM

OpenPrinting CUPS: Heap overflow in `get_options()`

Title source: cna
STIX 2.1

Description

OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-based buffer overflow in the CUPS scheduler when building filter option strings from job attribute. At time of publication, there are no publicly available patches.

Scores

CVSS v3 5.3
EPSS 0.0005
EPSS Percentile 16.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-122
Status published
Products (2)
openprinting/cups < 2.4.16
OpenPrinting/cups <= 2.4.16
Published Apr 03, 2026
Tracked Since Apr 04, 2026