#VU125820 Out-of-bounds read in cups
Published: April 11, 2026
cups
OpenPrinting
Description
The vulnerability allows a local user to cause a denial of service.
The vulnerability exists due to out-of-bounds read in cupsdSetPrinterAttr() marker-types parsing in scheduler/printers.c when parsing marker-types attribute values that end with a trailing hyphen character. A local user can provide a specially crafted marker-types value to cause a denial of service.
Exploitation can occur through a malicious backend or a compromised printer supplying crafted IPP attributes.