{"id":"openSUSE-SU-2026:21850-1","summary":"Security update for cups-filters","details":"This update for cups-filters fixes the following issues:\n\nChanges in cups-filters:\n\n- CVE-2026-64611: Fixed Infinite-loop CPU-exhaustion DoS in\n   cfIEEE1284NormalizeMakeModel on empty MDL field.\n  A user who controls an IEEE-1284 device ID consumed by\n   `cfIEEE1284GetMakeModel` can drive\n   `cfIEEE1284NormalizeMakeModel` into an infinite loop.\n  (bsc#1273145,GHSA-rcq7-rv5g-j3r4)\n\n- CVE-2026-64612: Fixed Malformed PNG aborts CUPS image filter process\n   (missing libpng setjmp recovery)\n  A authenticated client that can submit an image print job\n   can abort the CUPS filter process by supplying a malformed PNG.\n  (bsc#1273146,GHSA-7mxj-cfq5-84ch)\n\n- Provide cups-browsed as separated cups-filters-cups-browsed\n  sub-package so users can uninstall this sub-package\n  to completely avoid the generic security risk of cups-browsed.\n  cups-browsed auto-creates local print queues for printers which\n  are announced via DNS-SD. It is a generic security risk when a\n  service (cups-browsed.service) accepts any (possibly malicious)\n  incoming information from any host in the local network\n  (i.e. any DNS-SD announcements) and from that information\n  it auto-creates print queue configurations for CUPS\n  (where its server program cupsd runs as root).\n  For more information see the openSUSE support database article\n  https://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings\n\n- Fixed a regression \"Error about PPD file during 'driverless' printer setup\"\n  (boo#1256868) and \"ppd pull out from [driverless] printer feature broken\"\n  (bsc#1256977)\n\n- unbreak qpdf [bsc#1253678]\n\n- CVE-2024-47176: Fixed cups-browsed binds to UDP INADDR_ANY:631 (bsc#1230939)\n  and to avoid CVE-2024-47850 \"cups-browsed can be abused to\n  initiate remote DDoS against third-party targets\" (bsc#1231294)\n  by removing legacy CUPS Browsing support in cups-browsed\n  (introduced 2012) which is no longer needed nowadays.\n  CUPS browsing was removed from CUPS since version 1.6.\n  Legacy CUPS Browsing is a generic security risk, see the\n  section \"Automated print queue setup via cups-browsed\" in\n  https://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings\n\n- CVE-2024-47076: Fixed lack of input sanitization in cfGetPrinterAttributes5 (bsc#1230937)\n\n- CVE-2024-47175: Fixed lack of input sanitization in _ppdCreateFromIPP() (bsc#1230932)\n\n- In general regarding CUPS and cups-browsed security issues see\n  https://en.opensuse.org/SDB:CUPS_and_SANE_Firewall_settings\n","modified":"2026-09-15T18:23:27.066972430Z","published":"2026-09-14T13:25:38Z","related":["CVE-2024-47076","CVE-2024-47175","CVE-2024-47176","CVE-2024-47850","CVE-2026-64611","CVE-2026-64612"],"upstream":["CVE-2024-47076","CVE-2024-47175","CVE-2024-47176","CVE-2024-47850","CVE-2026-64611","CVE-2026-64612"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1230932"},{"type":"REPORT","url":"https://bugzilla.suse.com/1230937"},{"type":"REPORT","url":"https://bugzilla.suse.com/1230939"},{"type":"REPORT","url":"https://bugzilla.suse.com/1231294"},{"type":"REPORT","url":"https://bugzilla.suse.com/1253678"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256868"},{"type":"REPORT","url":"https://bugzilla.suse.com/1256977"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273145"},{"type":"REPORT","url":"https://bugzilla.suse.com/1273146"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-47076"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-47175"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-47176"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-47850"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64611"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-64612"}],"affected":[{"package":{"name":"cups-filters","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/cups-filters&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.28.17-bp160.2.1"}]}],"ecosystem_specific":{"binaries":[{"cups-filters-cups-browsed":"1.28.17-bp160.2.1","cups-filters-devel":"1.28.17-bp160.2.1","cups-filters":"1.28.17-bp160.2.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21850-1.json"}}],"schema_version":"1.9.0"}