<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-04T03:22:03.766216+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2025:15700</id>
    <title>ALSA-2025:15700 — Important: cups security update</title>
    <updated>2026-10-04T03:22:04.041261+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: cups, AlmaLinux:9: cups-client, AlmaLinux:9: cups-devel, AlmaLinux:9: cups-filesystem, AlmaLinux:9: cups-ipptool, AlmaLinux:9: cups-libs, AlmaLinux:9: cups-lpd, AlmaLinux:9: cups-printerapp</p>
<p>The Common UNIX Printing System (CUPS) provides a portable printing layer for  
Linux, UNIX, and similar operating systems.</p>
<p>Security Fix(es):</p>
<p>* cups: Null Pointer Dereference in CUPS ipp_read_io() Leading to Remote DoS</p>
<p>(CVE-2025-58364)</p>
<p>* cups: Authentication Bypass in CUPS Authorization Handling (CVE-2025-58060)</p>
<p>For more details about the security issue(s), including the impact, a CVSS  
score, acknowledgments, and other related information, refer to the CVE page(s)  
listed in the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2025:15700"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-12439</id>
    <title>bdu:2025-12439</title>
    <updated>2026-10-04T03:22:04.041332+00:00</updated>
    <content>bdu:2025-12439</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-12439"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2025-58364</id>
    <title>BELL-CVE-2025-58364</title>
    <updated>2026-10-04T03:22:04.041353+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p><strong>Affected:</strong> Alpaquita:23: cups, Alpaquita:25: cups, Alpaquita:stream: cups</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2025-58364"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-260055</id>
    <title>EUVD-2026-260055</title>
    <updated>2026-10-04T03:22:04.041373+00:00</updated>
    <content>EUVD-2026-260055</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-260055"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58364</id>
    <title>fkie_cve-2025-58364</title>
    <updated>2026-10-04T03:22:04.041385+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation of printer attributes causes null dereference in the libcups library. This is a remote DoS vulnerability available in local subnet in default configurations. It can cause the cups &amp; cups-browsed to crash, on all the machines in local network who are listening for printers (so by default for all regular linux machines). On systems where the vulnerability CVE-2024-47176 (cups-filters 1.x/cups-browsed 2.x vulnerability) was not fixed, and the firewall on the machine does not reject incoming communication to IPP port, and the machine is set to be available to public internet, attack vector "Network" is possible. The current versions of CUPS and cups-browsed projects have the attack vector "Adjacent" in their default configurations. Version 2.4.13 contains a patch for CVE-2025-58364.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-58364"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-58364</id>
    <title>msrc_CVE-2025-58364 — cups: Remote DoS via null dereference</title>
    <updated>2026-10-04T03:22:04.041412+00:00</updated>
    <content>msrc_CVE-2025-58364</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-58364"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2025-2334</id>
    <title>OESA-2025-2334 — cups security update</title>
    <updated>2026-10-04T03:22:04.041428+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:24.03-LTS-SP2: cups, openEuler:20.03-LTS-SP4: cups, openEuler:22.03-LTS-SP3: cups, openEuler:22.03-LTS-SP4: cups, openEuler:24.03-LTS: cups, openEuler:24.03-LTS-SP1: cups</p>
<p>CUPS is the standards-based, open source printing system developed by Apple Inc. for UNIX®-like operating systems. CUPS uses the Internet Printing Protocol (IPP) to support printing to local and network printers.

Security Fix(es):</p>
<p>[&amp;apos;Hi all,\n\nthere is important security vulnerability in CUPS:\n\n\n\xa0\xa0 Description\n\n\n\xa0\xa0\xa0\xa0 Summary&amp;apos;, &amp;apos;Details&amp;apos;, &amp;apos;PoC\n\n- Configure CUPS with |DefaultAuthType Negotiate|.\n- Start CUPS&amp;apos;, &amp;apos;- cat /etc/cups/cupsd.conf\nhaha\n\n\n\xa0\xa0\xa0\xa0 Impact&amp;apos;, &amp;apos;Patch&amp;apos;, &amp;apos;Have a nice day,\n\n\nZdenek Dohnal\n\n--\nZdenek Dohnal\nSenior Software Engineer\nRed Hat, BRQ-TPBC&amp;apos;](CVE-2025-58060)</p>
<p>[&amp;apos;Hi all!&amp;apos;, &amp;apos;Description\n\n\n\xa0\xa0\xa0\xa0 Summary&amp;apos;, &amp;apos;Details\n\nThe combination of:&amp;apos;, &amp;apos;Is shown in two places in OpenPrinting:\n\n|cups/scheduler/ipp.c libcupsfilters/cupsfilters/ipp.c |&amp;apos;, &amp;apos;PoC&amp;apos;, &amp;apos;Impact&amp;apos;, &amp;apos;Metrics:\n\n\n\xa0\xa0\xa0\xa0\xa0\xa0 CVSS v3 base metrics\n\nAttack vector Adjacent\nAttack complexity Low\nPrivileges required None\nUser interaction None\nScope Unchanged\nConfidentiality None\nIntegrity None\nAvailability High\n\nCredit -&amp;apos;, &amp;apos;Patch&amp;apos;, &amp;apos;Have a nice day!\n\n\nZdenek\n\n--\nZdenek Dohnal\nSenior Software Engineer\nRed Hat, BRQ-TPBC&amp;apos;](CVE-2025-58364)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2025-2334"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15562-1</id>
    <title>openSUSE-SU-2025:15562-1 — cups-2.4.14-1.1 on GA media</title>
    <updated>2026-10-04T03:22:04.041468+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cups-2.4.14-1.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2025:15562-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:16590</id>
    <title>RHSA-2025:16590 — Red Hat Security Advisory: cups security update</title>
    <updated>2026-10-04T03:22:04.041485+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>cups: Authentication Bypass in CUPS Authorization Handling cups: Null Pointer Dereference in CUPS ipp_read_io() Leading to Remote DoS</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:16590"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2025:03178-1</id>
    <title>SUSE-SU-2025:03178-1 — Security update for cups</title>
    <updated>2026-10-04T03:22:04.041502+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for cups</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2025:03178-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58364</id>
    <title>UBUNTU-CVE-2025-58364</title>
    <updated>2026-10-04T03:22:04.041517+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:Pro:16.04:LTS: cups, Ubuntu:Pro:18.04:LTS: cups, Ubuntu:Pro:20.04:LTS: cups, Ubuntu:22.04:LTS: cups, Ubuntu:24.04:LTS: cups</p>
<p>OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation of printer attributes causes null dereference in the libcups library. This is a remote DoS vulnerability available in local subnet in default configurations. It can cause the cups &amp; cups-browsed to crash, on all the machines in local network who are listening for printers (so by default for all regular linux machines). On systems where the vulnerability CVE-2024-47176 (cups-filters 1.x/cups-browsed 2.x vulnerability) was not fixed, and the firewall on the machine does not reject incoming communication to IPP port, and the machine is set to be available to public internet, attack vector "Network" is possible. The current versions of CUPS and cups-browsed projects have the attack vector "Adjacent" in their default configurations. Version 2.4.13 contains a patch for CVE-2025-58364.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58364"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2039</id>
    <title>WID-SEC-W-2025-2039 — CUPS: Mehrere Schwachstellen</title>
    <updated>2026-10-04T03:22:04.041547+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein Angreifer kann mehrere Schwachstellen in CUPS ausnutzen, um Sicherheitsvorkehrungen zu umgehen und um einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2039"/>
  </entry>
</feed>
