CVE-2026-107890
Received Received - Intake

NULL Pointer Dereference in OpenPrinting CUPS

Vulnerability report for CVE-2026-107890, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: MITRE

Description

OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference caused by repeated IPP group tags in job-creation requests. IPP parsing creates unnamed separator attributes with IPP_TAG_ZERO, but add_job() converts these separators to IPP_TAG_JOB. During job startup, get_options()/ipp_length() subsequently calls strlen() on a NULL attribute name, terminating cupsd and disrupting all queues. A single crafted Print-Job request can trigger the crash when the client can reach the scheduler and submit jobs to an accepting, enabled queue supporting the submitted document format. Anonymous submission is possible when permitted by listener and access-control configuration.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
OpenPrinting CUPS 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-476 The product dereferences a pointer that it expects to be valid but is NULL.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a NULL pointer dereference flaw in OpenPrinting CUPS versions before 2.4.20. It occurs when repeated IPP group tags in job-creation requests create unnamed separator attributes. During processing, these separators are incorrectly converted to job attributes, leading to a NULL attribute name. When cupsd attempts to call strlen() on this NULL name, it crashes the daemon, disrupting all print queues.

Detection Guidance

Monitor for crashes in the cupsd process or check CUPS logs for segmentation faults. Use commands like 'systemctl status cups' or 'journalctl -u cups' to detect crashes. Network traffic analysis tools like Wireshark can inspect IPP requests for repeated group tags.

Impact Analysis

An unauthenticated attacker could exploit this by sending a crafted Print-Job request to a vulnerable CUPS server. This would crash the cupsd process, halting all print services managed by that server. The attack requires network access to the scheduler and permission to submit jobs anonymously, but it can disrupt printing for all users relying on the affected system.

Compliance Impact

This vulnerability primarily causes service disruption rather than data breaches or unauthorized access. However, prolonged downtime of print services could impact compliance with availability requirements in GDPR or HIPAA. Organizations must ensure timely patching to maintain operational continuity and avoid potential compliance violations.

Mitigation Strategies

Upgrade CUPS to version 2.4.20 or later. Disable anonymous job submissions if enabled. Restrict network access to the CUPS scheduler to prevent unauthenticated requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107890. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart