Alerts This Week
Warning Icon 1 938
Alerts This Week
Warning Icon 1 938

SUSE CUPS Significant Security Update Released for 2026-21871-1

suse
Calendar Grey June 2, 2026
Dist Suse Esm H88
Eight vulnerabilities fixed in SUSE cups update released 2026-05-26, ensuring important security updates for systems.
An update that solves eight vulnerabilities can now be installed.

Summary

## This update for cups fixes the following issues * CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup (bsc#1261572). * CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (bsc#1261571). * CVE-2026-34979: Heap overflow in `get_options()` (bsc#1261570). * CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (bsc#1261569). * CVE-2026-34990: Local print admin token disclosure using temporary printers (bsc#1261568). * CVE-2026-39314: negative `job-password-supported` attribute can lead to a denial of service (bsc#1261743). * CVE-2026-39316: dangling subscription pointer can lead to a denial of service (bsc#1261742).

References

* bsc#1261568

* bsc#1261569

* bsc#1261570

* bsc#1261571

* bsc#1261572

* bsc#1261742

* bsc#1261743

* bsc#1263116

Cross-

* CVE-2026-27447

* CVE-2026-34978

* CVE-2026-34979

* CVE-2026-34980

* CVE-2026-34990

* CVE-2026-39314

* CVE-2026-39316

* CVE-2026-41079

CVSS scores:

* CVE-2026-27447 ( SUSE ): 4.8 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N

* CVE-2026-27447 ( NVD ): 6.3 CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N

* CVE-2026-27447 ( NVD ): 4.8 CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:U/C:H/I:L/A:N

* CVE-2026-34978 ( SUSE ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

* CVE-2026-34978 ( NVD ): 6.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L

* CVE-2026-34979 ( SUSE ): 5.3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2026:21871-1
Release Date: 2026-05-26T11:42:40Z
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here