Security update for cups
| Announcement ID: | SUSE-SU-2026:21787-1 |
|---|---|
| Release Date: | 2026-05-26T11:57:42Z |
| Rating: | important |
| References: | |
| Cross-References: | |
| CVSS scores: |
|
| Affected Products: |
|
An update that solves eight vulnerabilities can now be installed.
Description:
This update for cups fixes the following issues
- CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup (bsc#1261572).
- CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (bsc#1261571).
- CVE-2026-34979: Heap overflow in
get_options()(bsc#1261570). - CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach
lpcode execution over the network (bsc#1261569). - CVE-2026-34990: Local print admin token disclosure using temporary printers (bsc#1261568).
- CVE-2026-39314: negative
job-password-supportedattribute can lead to a denial of service (bsc#1261743). - CVE-2026-39316: dangling subscription pointer can lead to a denial of service (bsc#1261742).
- CVE-2026-41079: crafted SNMP response can lead to stack-based out-of-bounds read and sensitive memory disclosure (bsc#1263116).
Changes for cups:
- Version upgrade to 2.4.19
Patch Instructions:
To install this SUSE update use the SUSE recommended
installation methods like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
-
SUSE Linux Micro 6.0
zypper in -t patch SUSE-SLE-Micro-6.0-729=1
Package List:
-
SUSE Linux Micro 6.0 (aarch64 s390x x86_64)
- libcups2-debuginfo-2.4.19-1.1
- libcups2-2.4.19-1.1
- cups-config-2.4.19-1.1
- cups-debugsource-2.4.19-1.1
References:
- https://www.suse.com/security/cve/CVE-2026-27447.html
- https://www.suse.com/security/cve/CVE-2026-34978.html
- https://www.suse.com/security/cve/CVE-2026-34979.html
- https://www.suse.com/security/cve/CVE-2026-34980.html
- https://www.suse.com/security/cve/CVE-2026-34990.html
- https://www.suse.com/security/cve/CVE-2026-39314.html
- https://www.suse.com/security/cve/CVE-2026-39316.html
- https://www.suse.com/security/cve/CVE-2026-41079.html
- https://bugzilla.suse.com/show_bug.cgi?id=1261568
- https://bugzilla.suse.com/show_bug.cgi?id=1261569
- https://bugzilla.suse.com/show_bug.cgi?id=1261570
- https://bugzilla.suse.com/show_bug.cgi?id=1261571
- https://bugzilla.suse.com/show_bug.cgi?id=1261572
- https://bugzilla.suse.com/show_bug.cgi?id=1261742
- https://bugzilla.suse.com/show_bug.cgi?id=1261743
- https://bugzilla.suse.com/show_bug.cgi?id=1263116