CVE-2026-107888
Received Received - Intake

NULL Pointer Dereference in OpenPrinting CUPS

Vulnerability report for CVE-2026-107888, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: MITRE

Description

OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create refers to a temporary printer that has been automatically deleted. Temporary-printer cleanup can remove the destination without canceling its held jobs, and the scheduler dereferences the NULL result of cupsdFindDest() while checking holding_new_jobs. This terminates cupsd and interrupts all queues managed by that process. In some plausible scenarios, an unprivileged submission can trigger this.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
OpenPrinting CUPS 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a NULL pointer dereference in the CUPS (Common UNIX Printing System) daemon, specifically in the cupsdCheckJobs() function. It occurs when a job marked as 'job-held-on-create' refers to a temporary printer that has been automatically deleted. The function tries to access the printer's attributes without checking if the printer still exists, causing the cupsd process to crash. This affects all print queues managed by the scheduler.

Detection Guidance

Check CUPS version with 'cups-config --version' or 'dpkg -l cups' on Debian-based systems. Look for versions prior to 2.4.20. Monitor cupsd logs for crashes or NULL pointer errors. Check for temporary printers that were deleted but have held jobs with 'lpstat -a' or 'cupsctl --debug-logging' for detailed scheduler logs.

Impact Analysis

The vulnerability can cause a denial of service for all print queues managed by the affected cupsd process. This means printing services may become unavailable, interrupting all print jobs managed by that process. In some cases, an unprivileged user could trigger this issue if a temporary queue is configured to hold jobs.

Compliance Impact

This vulnerability primarily causes a denial of service by crashing the CUPS daemon, interrupting print queues. It does not directly impact data confidentiality or integrity, which are key focus areas for GDPR and HIPAA. However, service disruption could indirectly affect compliance if printing is required for logging or documentation under these regulations.

Mitigation Strategies

Upgrade CUPS to version 2.4.20 or later immediately. Restart the cupsd service after upgrade. Review and cancel any held jobs associated with deleted temporary printers using 'cancel' command. Disable automatic temporary printer cleanup if possible until upgrade is completed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107888. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart