Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 511
Alerts This Week
Warning Icon 1 511

Ubuntu 16.04 CUPS Critical Control Character Injection CVE-2026-34980

ubuntu
Calendar Grey July 21, 2026
Scroller Ubuntu
CUPS in Ubuntu could be exploited for remote code execution via crafted print job requests, update recommended immediately.
CUPS could be made to run programs as the lp user if it received specially crafted print job requests.

Summary

CUPS could be made to run programs as the lp user if it received specially crafted print job requests.

Software Description:

- cups: Common UNIX Printing System(tm)

Details:

It was discovered that CUPS did not properly filter control characters in IPP string attributes and PPD keywords. An unauthenticated attacker could exploit this to execute arbitrary code as the lp user on systems with shared target queues.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 16.04 LTS
  cups                            2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro
  cups-bsd                        2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro
  cups-client                     2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro
  cups-common                     2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro
  cups-core-drivers               2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro
  cups-daemon                     2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro
  libcups2                        2.1.3-4ubuntu0.11+esm13
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8578-1

CVE-2026-34980

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8578-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.