CVE-2026-55480
Public on 2026-10-09
Modified on 2026-10-09
Description
When a printer is added or modified with a model PPD, the cupsd scheduler (running as root) calls copy_model() in scheduler/ipp.c, which writes the driver-generated PPD to a temporary file. The tempfile path is fully predictable (/number>.ppd, where con->number is the sequential client connection id) and is opened with open(tempfile, O_WRONLY | O_CREAT | O_TRUNC, 0600) — without O_EXCL and without O_NOFOLLOW. TempDir (/var/spool/cups/tmp) is mode 01770 root:lp, i.e. writable by the lp group that print filters run under. An lp-group process can pre-plant a symlink at the
predicted path pointing at any root-owned file; root follows the symlink and truncates/overwrites the target, giving an lp → root arbitrary-file-write primitive. The codebase's own cups/tempfile.c opens temporaries safely with O_RDWR|O_CREAT|O_EXCL|O_NOFOLLOW; copy_model() is the inconsistent outlier.
NOTE: https://github.com/OpenPrinting/cups/security/advisories/GHSA-jj94-x3qh-ffp9
NOTE: Fixed by: https://github.com/OpenPrinting/cups/commit/98adfd855950e806508f961d5438ad32e26aac62 (v2.4.20)
predicted path pointing at any root-owned file; root follows the symlink and truncates/overwrites the target, giving an lp → root arbitrary-file-write primitive. The codebase's own cups/tempfile.c opens temporaries safely with O_RDWR|O_CREAT|O_EXCL|O_NOFOLLOW; copy_model() is the inconsistent outlier.
NOTE: https://github.com/OpenPrinting/cups/security/advisories/GHSA-jj94-x3qh-ffp9
NOTE: Fixed by: https://github.com/OpenPrinting/cups/commit/98adfd855950e806508f961d5438ad32e26aac62 (v2.4.20)
Severity
See what this means
CVSS v3 Base Score
See breakdown
Affected Packages
| Platform | Package | Release Date | Advisory | Status |
|---|---|---|---|---|
| Amazon Linux 2 - Core | cups | Pending Fix | ||
| Amazon Linux 2023 | cups | Pending Fix | ||
| Amazon Linux 2027 Preview | cups | Pending Fix | ||
| Amazon Linux 2027 Preview | cups-browsed | Not Affected | ||
| Amazon Linux 2 - Core | cups-filters | Not Affected | ||
| Amazon Linux 2023 | cups-filters | Not Affected | ||
| Amazon Linux 2027 Preview | cups-filters | Not Affected | ||
| Amazon Linux 2 - Core | cups-pk-helper | Not Affected | ||
| Amazon Linux 2023 | cups-pk-helper | Not Affected | ||
| Amazon Linux 2027 Preview | cups-pk-helper | Not Affected | ||
| Amazon Linux 2027 Preview | libcupsfilters | Not Affected | ||
| Amazon Linux 2 - Core | python-cups | Not Affected | ||
| Amazon Linux 2023 | python-cups | Not Affected | ||
| Amazon Linux 2027 Preview | python-cups | Not Affected |
CVSS Scores
| Score Type | Score | Vector | |
|---|---|---|---|
| Amazon Linux | CVSSv3 | 5.7 | CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:H/A:H |