CVE-2025-58364
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-09-11

Last updated on: 2025-11-04

Assigner: GitHub, Inc.

Description
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation of printer attributes causes null dereference in the libcups library. This is a remote DoS vulnerability available in local subnet in default configurations. It can cause the cups & cups-browsed to crash, on all the machines in local network who are listening for printers (so by default for all regular linux machines). On systems where the vulnerability CVE-2024-47176 (cups-filters 1.x/cups-browsed 2.x vulnerability) was not fixed, and the firewall on the machine does not reject incoming communication to IPP port, and the machine is set to be available to public internet, attack vector "Network" is possible. The current versions of CUPS and cups-browsed projects have the attack vector "Adjacent" in their default configurations. Version 2.4.13 contains a patch for CVE-2025-58364.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-09-11
Last Modified
2025-11-04
Generated
2026-05-07
AI Q&A
2025-09-11
EPSS Evaluated
2026-05-05
NVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
openprinting cups to 2.4.13 (exc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

This vulnerability in OpenPrinting CUPS (version 2.4.12 and earlier) involves unsafe deserialization and validation of printer attributes in the libcups library, which leads to a null dereference. This flaw can cause the cups and cups-browsed services to crash on all machines in the local network that listen for printers, resulting in a denial of service (DoS).


How can this vulnerability impact me? :

The vulnerability can cause a denial of service by crashing the cups and cups-browsed services on all affected machines in the local network. If the system is exposed to the public internet without proper firewall restrictions and has not fixed related vulnerabilities, an attacker could exploit this remotely, causing disruption of printing services.


What immediate steps should I take to mitigate this vulnerability?

Upgrade CUPS and cups-browsed to version 2.4.13 or later, which contains the patch for CVE-2025-58364. Additionally, ensure that your firewall blocks incoming communication to the IPP port if the system is exposed to public internet, and verify that the vulnerability CVE-2024-47176 is fixed on your systems to reduce attack vectors.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart