CVE-2026-107886
Public on 2026-10-09
Modified on 2026-10-10
Description
OpenPrinting CUPS before 2.4.20 contains a double-free in printer-class management. When CUPS-Add-Modify-Class replaces an existing class member list, add_class() frees pclass->printers without clearing the pointer. If subsequent validation fails, the class retains the dangling pointer; CUPS-Delete-Class subsequently frees the same allocation in cupsdDeletePrinter(). A client authorized to modify and delete classes can cause scheduler-wide denial of service. The default policy requires @SYSTEM privileges.
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | cups | Pending Fix | ||
| Amazon Linux 2023 | cups | Pending Fix | ||
| Amazon Linux 2027 Preview | cups | Pending Fix | ||
| Amazon Linux 2027 Preview | cups-browsed | Not Affected | ||
| Amazon Linux 2 - Core | cups-filters | Not Affected | ||
| Amazon Linux 2023 | cups-filters | Not Affected | ||
| Amazon Linux 2027 Preview | cups-filters | Not Affected | ||
| Amazon Linux 2 - Core | cups-pk-helper | Not Affected | ||
| Amazon Linux 2023 | cups-pk-helper | Not Affected | ||
| Amazon Linux 2027 Preview | cups-pk-helper | Not Affected | ||
| Amazon Linux 2027 Preview | libcupsfilters | Not Affected | ||
| Amazon Linux 2 - Core | python-cups | Not Affected | ||
| Amazon Linux 2023 | python-cups | Not Affected | ||
| Amazon Linux 2027 Preview | python-cups | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 4.4 | CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H |