Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Ubuntu 26.04 CUPS Critical Denial of Service and Access Flaws USN-8405-1

Ubuntu Large Esm H500
Several security issues were fixed in CUPS.
==========================================================================
Ubuntu Security Notice USN-8405-1
June 08, 2026

cups vulnerabilities
==========================================================================

A security issue affects these releases of Ubuntu and its derivatives:

- Ubuntu 26.04 LTS
- Ubuntu 25.10
- Ubuntu 24.04 LTS
- Ubuntu 22.04 LTS

Summary:

Several security issues were fixed in CUPS.

Software Description:
- cups: Common UNIX Printing System(tm)

Details:

Ariel Silver discovered that CUPS incorrectly handled username comparisons
during authorization checks. A local attacker could possibly use this issue
to gain unauthorized access to restricted operations. (CVE-2026-27447)

Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
notify-recipient-uri values in the RSS notifier. A remote attacker could
possibly use this issue to overwrite lp-writable files and cause a denial
of service. (CVE-2026-34978)

Jacob Newman discovered that CUPS incorrectly handled filter option strings
when processing job attributes. An attacker could use this issue to cause
CUPS to crash, resulting in a denial of service, or possibly execute
arbitrary code. (CVE-2026-34979)

Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
page-border values in shared PostScript queues. A remote attacker could
possibly use this issue to execute arbitrary code. (CVE-2026-34980)

Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled
localhost authentication to attacker-controlled IPP services. A local
attacker could possibly use this issue to overwrite arbitrary files
and execute arbitrary code. (CVE-2026-34990)

Tomer Fichman discovered that CUPS incorrectly handled negative
job-password-supported values. A local attacker could possibly use this
issue to cause CUPS to crash, resulting in a denial of service.
(CVE-2026-39314)

Tomer Fichman discovered that CUPS incorrectly handled temporary printer
deletion. An attacker could possibly use this issue to cause CUPS to crash,
resulting in a denial of service, or to execute arbitrary code.
(CVE-2026-39316)

Tomer Fichman discovered that CUPS incorrectly handled certain malformed
SNMP responses. An attacker could possibly use this issue to obtain
sensitive information. (CVE-2026-41079)

Update instructions:

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 26.04 LTS
  cups                            2.4.16-1ubuntu1.2
  cups-daemon                     2.4.16-1ubuntu1.2

Ubuntu 25.10
  cups                            2.4.12-0ubuntu3.9
  cups-daemon                     2.4.12-0ubuntu3.9

Ubuntu 24.04 LTS
  cups                            2.4.7-1.2ubuntu7.13
  cups-daemon                     2.4.7-1.2ubuntu7.13

Ubuntu 22.04 LTS
  cups                            2.4.1op1-1ubuntu4.20
  cups-daemon                     2.4.1op1-1ubuntu4.20

In general, a standard system update will make all the necessary changes.

References:
  https://ubuntu.com/security/notices/USN-8405-1
  CVE-2026-27447, CVE-2026-34978, CVE-2026-34979, CVE-2026-34980,
  CVE-2026-34990, CVE-2026-39314, CVE-2026-39316, CVE-2026-41079

Package Information:
  https://launchpad.net/ubuntu/+source/cups/2.4.16-1ubuntu1.2
  https://launchpad.net/ubuntu/+source/cups/2.4.12-0ubuntu3.9
  https://launchpad.net/ubuntu/+source/cups/2.4.7-1.2ubuntu7.13
  https://launchpad.net/ubuntu/+source/cups/2.4.1op1-1ubuntu4.20

Ubuntu 26.04 CUPS Critical Denial of Service and Access Flaws USN-8405-1

ubuntu
Calendar Grey June 8, 2026
Dist Ubuntu Esm H88
Critical security issues in CUPS fixed across multiple Ubuntu versions to prevent unauthorized access.
Several security issues were fixed in CUPS.

Summary

A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 26.04 LTS - Ubuntu 25.10 - Ubuntu 24.04 LTS - Ubuntu 22.04 LTS Summary: Several security issues were fixed in CUPS. Software Description: - cups: Common UNIX Printing System(tm) Details: Ariel Silver discovered that CUPS incorrectly handled username comparisons during authorization checks. A local attacker could possibly use this issue to gain unauthorized access to restricted operations. (CVE-2026-27447) Asim Viladi Oglu Manizada discovered that CUPS incorrectly handled notify-recipient-uri values in the RSS notifier. A remote attacker could possibly use this issue to overwrite lp-writable files and cause a denial of service. (CVE-2026-34978) Jacob Newman discovered that CUPS incorrectly handled filter option strings when processing job attributes. An attacker could use this issue to cause CUPS to crash, resulting in a denial of service, or possibly execute arbitrary code. (CVE-2026-34979) Asi...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following package versions: Ubuntu 26.04 LTS cups 2.4.16-1ubuntu1.2 cups-daemon 2.4.16-1ubuntu1.2 Ubuntu 25.10 cups 2.4.12-0ubuntu3.9 cups-daemon 2.4.12-0ubuntu3.9 Ubuntu 24.04 LTS cups 2.4.7-1.2ubuntu7.13 cups-daemon 2.4.7-1.2ubuntu7.13 Ubuntu 22.04 LTS cups 2.4.1op1-1ubuntu4.20 cups-daemon 2.4.1op1-1ubuntu4.20 In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8405-1

CVE-2026-27447, CVE-2026-34978, CVE-2026-34979, CVE-2026-34980,

CVE-2026-34990, CVE-2026-39314, CVE-2026-39316, CVE-2026-41079

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8405-1

Package Information

https://launchpad.net/ubuntu/+source/cups/2.4.16-1ubuntu1.2 https://launchpad.net/ubuntu/+source/cups/2.4.12-0ubuntu3.9 https://launchpad.net/ubuntu/+source/cups/2.4.7-1.2ubuntu7.13 https://launchpad.net/ubuntu/+source/cups/2.4.1op1-1ubuntu4.20

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here