Re: AI-discovered recent CUPS vulnerabilities going through the news

Zdenek Dohnal <[email protected]> Thu, 16 Apr 2026 09:15:52 +0200
Newsgroups dev.linux.lists.printing-architecture
Message-ID <[email protected]>
Till,

AFAIK those vulnerabilities - CVE-2026-34980 and CVE-2026-39316 - were 
fixed by Mike at the time they were published, so OpenPrinting/CUPS is 
fixed - they are present in both master and 2.4.x branches.

The only thing which remains is to do 2.4.x release, which I plan to do 
today. For now I updated the advisories to mention the commits which fix 
them.

I'm sorry for the delay, I had to do CVE fix for my other components :( .


Zdenek

On 4/16/26 04:29, Till Kamppeter wrote:
> [ Resent to correct list address, pleas only answer to this one, with 
> "Reply to
>   all". ]
>
> When chatting with the hosts of Destination Linux, they told me about 
> following posts:
>
> https://www.theregister.com/2026/04/06/ai_agents_cups_server_rce/
>
> https://cyberpress.org/cups-vulnerability/
>
> https://cybersecuritynews.com/cups-vulnerability-remote-attack/
>
> https://www.scworld.com/brief/new-cups-vulnerabilities-threaten-rce-network-breaches 
>
>
>
> Summary by Ryan DASgeek
> -----------------------
>
> -----
>
> The attack doesn't require a user to "click" a link or download a 
> file. Instead, it exploits how Linux handles printer discovery and 
> print job metadata. Here is the step-by-step breakdown of how it moves 
> from the network to a root terminal:
>
>     Discovery (The Hook): The attacker identifies a Linux machine with 
> CUPS exposed (usually on UDP port 631). They send a specially crafted 
> packet that "advertises" a new, fake printer on the network. Because 
> many Linux distributions have cups-browsed enabled by default for 
> convenience, the computer automatically "sees" this printer and adds 
> it to the system.
>
>     The "Page-Border" Injection (The Payload): The core of the April 
> 2026 issue (CVE-2026-34980) lies in how CUPS parses print options. The 
> attacker sends a print job to this fake printer containing "smuggled" 
> newlines within the page-border attribute. CUPS fails to sanitize 
> these hidden commands.
>
>     Command Execution: When the system processes the job, it gets 
> tricked into treating part of the malicious metadata as a trusted 
> configuration file. This allows the attacker to execute commands as 
> the lp (printer) user.
>
>     Escalation to Root (The Terminal Access): Once the attacker has a 
> "foothold" as the lp user, they utilize a second flaw 
> (CVE-2026-39316), which is a Use-After-Free vulnerability in the CUPS 
> scheduler. By triggering a crash and memory corruption while the 
> system is deleting temporary printers, the attacker can escalate their 
> privileges from a restricted service account to full root access. At 
> this point, they have complete control over the terminal and the 
> entire operating system.
>
> -----
>
> Michael, I did not see that, probably due to the flood of 
> bug/vulnerability report coming in in the last days due to several 
> contributors using AI.
>
> I hope you are aware of these (or of the fact that the combination can 
> lead to remote root).
>
> Thanks a lot, Ryan for passing this on to me.
>
>    Till
>
>
-- 
Zdenek Dohnal
Senior Software Engineer
Red Hat, BRQ-TPBC