CVE-2026-87875
Awaiting Analysis Awaiting Analysis - Queue

Heap Out-of-Bounds Read in CUPS SNMP Parsing

Vulnerability report for CVE-2026-87875, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-12

Assigner: redhat-SADP

Description

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-12
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
apple cups *
openprinting cups to master (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-87875 is a heap out-of-bounds read vulnerability in CUPS (Common UNIX Printing System). The cupsUTF32ToUTF8() function in cups/transcode.c lacks a source-length bound check, allowing it to read past the end of the source buffer. This flaw is exploitable via SNMP supply-description parsing in backend/snmp-supplies.c when attacker-controlled content is processed.

Detection Guidance

To detect this vulnerability, monitor CUPS logs for crashes or memory errors during SNMP supply-description parsing. Check for heap corruption warnings in system logs when running commands like lpinfo or backend polling. Use tools like valgrind to detect out-of-bounds reads in cupsUTF32ToUTF8().

Commands to check: 1) Run 'lpinfo -v' to trigger SNMP polling and observe crashes. 2) Use 'valgrind --tool=memcheck cupsd' to detect memory issues. 3) Monitor '/var/log/cups/error_log' for heap-related errors.

Impact Analysis

This vulnerability could lead to memory disclosure, bypassing security mechanisms like ASLR, or causing crashes. It may expose adjacent heap memory or crash the backend process during supply-level polling (e.g., lpinfo or automatic backend polling) by a malicious or compromised printer. No authentication or user interaction is required beyond the CUPS host polling the printer over the network.

Compliance Impact

This vulnerability primarily involves a heap out-of-bounds read in CUPS software, which could lead to memory disclosure or crashes. It does not directly impact data confidentiality, integrity, or availability in a way that would violate GDPR or HIPAA requirements. However, if exploited, it might expose system memory that could contain sensitive information, potentially leading to secondary compliance issues depending on the context of use.

Mitigation Strategies

Immediately upgrade CUPS to a patched version if available. If no patch exists, disable SNMP supply polling by modifying CUPS configuration to avoid automatic printer polling. Restrict network access to CUPS ports (631) to trusted sources only.

Temporary mitigation: Disable SNMP support in CUPS by editing /etc/cups/cups-files.conf and setting 'BrowseRemoteProtocols' to none. Monitor vendor advisories for official patches and apply them promptly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-87875. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart