<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sun, 04 Oct 2026 00:36:59 +0000</lastBuildDate>
    <item>
      <title>ALSA-2025:15700 — Important: cups security update</title>
      <link>https://cve.radiocsirt.org/vuln/alsa-2025:15700</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: cups, AlmaLinux:9: cups-client, AlmaLinux:9: cups-devel, AlmaLinux:9: cups-filesystem, AlmaLinux:9: cups-ipptool, AlmaLinux:9: cups-libs, AlmaLinux:9: cups-lpd, AlmaLinux:9: cups-printerapp&lt;/p&gt;
&lt;p&gt;The Common UNIX Printing System (CUPS) provides a portable printing layer for  
Linux, UNIX, and similar operating systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cups: Null Pointer Dereference in CUPS ipp_read_io() Leading to Remote DoS&lt;/p&gt;
&lt;p&gt;(CVE-2025-58364)&lt;/p&gt;
&lt;p&gt;* cups: Authentication Bypass in CUPS Authorization Handling (CVE-2025-58060)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS  
score, acknowledgments, and other related information, refer to the CVE page(s)  
listed in the References section.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; AlmaLinux:9: cups, AlmaLinux:9: cups-client, AlmaLinux:9: cups-devel, AlmaLinux:9: cups-filesystem, AlmaLinux:9: cups-ipptool, AlmaLinux:9: cups-libs, AlmaLinux:9: cups-lpd, AlmaLinux:9: cups-printerapp&lt;/p&gt;
&lt;p&gt;The Common UNIX Printing System (CUPS) provides a portable printing layer for  
Linux, UNIX, and similar operating systems.&lt;/p&gt;
&lt;p&gt;Security Fix(es):&lt;/p&gt;
&lt;p&gt;* cups: Null Pointer Dereference in CUPS ipp_read_io() Leading to Remote DoS&lt;/p&gt;
&lt;p&gt;(CVE-2025-58364)&lt;/p&gt;
&lt;p&gt;* cups: Authentication Bypass in CUPS Authorization Handling (CVE-2025-58060)&lt;/p&gt;
&lt;p&gt;For more details about the security issue(s), including the impact, a CVSS  
score, acknowledgments, and other related information, refer to the CVE page(s)  
listed in the References section.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/alsa-2025:15700</guid>
    </item>
    <item>
      <title>bdu:2025-12439</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2025-12439</link>
      <description>bdu:2025-12439</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2025-12439</guid>
    </item>
    <item>
      <title>BELL-CVE-2025-58364</title>
      <link>https://cve.radiocsirt.org/vuln/bell-cve-2025-58364</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: cups, Alpaquita:25: cups, Alpaquita:stream: cups&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Alpaquita:23: cups, Alpaquita:25: cups, Alpaquita:stream: cups&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bell-cve-2025-58364</guid>
    </item>
    <item>
      <title>EUVD-2026-260055</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-260055</link>
      <description>EUVD-2026-260055</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-260055</guid>
    </item>
    <item>
      <title>fkie_cve-2025-58364</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2025-58364</link>
      <description>&lt;p&gt;OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation of printer attributes causes null dereference in the libcups library. This is a remote DoS vulnerability available in local subnet in default configurations. It can cause the cups &amp;amp; cups-browsed to crash, on all the machines in local network who are listening for printers (so by default for all regular linux machines). On systems where the vulnerability CVE-2024-47176 (cups-filters 1.x/cups-browsed 2.x vulnerability) was not fixed, and the firewall on the machine does not reject incoming communication to IPP port, and the machine is set to be available to public internet, attack vector &amp;#34;Network&amp;#34; is possible. The current versions of CUPS and cups-browsed projects have the attack vector &amp;#34;Adjacent&amp;#34; in their default configurations. Version 2.4.13 contains a patch for CVE-2025-58364.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation of printer attributes causes null dereference in the libcups library. This is a remote DoS vulnerability available in local subnet in default configurations. It can cause the cups &amp;amp; cups-browsed to crash, on all the machines in local network who are listening for printers (so by default for all regular linux machines). On systems where the vulnerability CVE-2024-47176 (cups-filters 1.x/cups-browsed 2.x vulnerability) was not fixed, and the firewall on the machine does not reject incoming communication to IPP port, and the machine is set to be available to public internet, attack vector &amp;#34;Network&amp;#34; is possible. The current versions of CUPS and cups-browsed projects have the attack vector &amp;#34;Adjacent&amp;#34; in their default configurations. Version 2.4.13 contains a patch for CVE-2025-58364.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2025-58364</guid>
    </item>
    <item>
      <title>msrc_CVE-2025-58364 — cups: Remote DoS via null dereference</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2025-58364</link>
      <description>msrc_CVE-2025-58364</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2025-58364</guid>
    </item>
    <item>
      <title>OESA-2025-2334 — cups security update</title>
      <link>https://cve.radiocsirt.org/vuln/oesa-2025-2334</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: cups, openEuler:20.03-LTS-SP4: cups, openEuler:22.03-LTS-SP3: cups, openEuler:22.03-LTS-SP4: cups, openEuler:24.03-LTS: cups, openEuler:24.03-LTS-SP1: cups&lt;/p&gt;
&lt;p&gt;CUPS is the standards-based, open source printing system developed by Apple Inc. for UNIX®-like operating systems. CUPS uses the Internet Printing Protocol (IPP) to support printing to local and network printers.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;[&amp;amp;apos;Hi all,\n\nthere is important security vulnerability in CUPS:\n\n\n\xa0\xa0 Description\n\n\n\xa0\xa0\xa0\xa0 Summary&amp;amp;apos;, &amp;amp;apos;Details&amp;amp;apos;, &amp;amp;apos;PoC\n\n- Configure CUPS with |DefaultAuthType Negotiate|.\n- Start CUPS&amp;amp;apos;, &amp;amp;apos;- cat /etc/cups/cupsd.conf\nhaha\n\n\n\xa0\xa0\xa0\xa0 Impact&amp;amp;apos;, &amp;amp;apos;Patch&amp;amp;apos;, &amp;amp;apos;Have a nice day,\n\n\nZdenek Dohnal\n\n--\nZdenek Dohnal\nSenior Software Engineer\nRed Hat, BRQ-TPBC&amp;amp;apos;](CVE-2025-58060)&lt;/p&gt;
&lt;p&gt;[&amp;amp;apos;Hi all!&amp;amp;apos;, &amp;amp;apos;Description\n\n\n\xa0\xa0\xa0\xa0 Summary&amp;amp;apos;, &amp;amp;apos;Details\n\nThe combination of:&amp;amp;apos;, &amp;amp;apos;Is shown in two places in OpenPrinting:\n\n|cups/scheduler/ipp.c libcupsfilters/cupsfilters/ipp.c |&amp;amp;apos;, &amp;amp;apos;PoC&amp;amp;apos;, &amp;amp;apos;Impact&amp;amp;apos;, &amp;amp;apos;Metrics:\n\n\n\xa0\xa0\xa0\xa0\xa0\xa0 CVSS v3 base metrics\n\nAttack vector Adjacent\nAttack complexity Low\nPrivileges required None\nUser interaction None\nScope Unchanged\nConfidentiality None\nIntegrity None\nAvailability High\n\nCredit -&amp;amp;apos;, &amp;amp;apos;Patch&amp;amp;apos;, &amp;amp;apos;Have a nice day!\n\n\nZdenek\n\n--\nZdenek Dohnal\nSenior Software Engineer\nRed Hat, BRQ-TPBC&amp;amp;apos;](CVE-2025-58364)&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; openEuler:24.03-LTS-SP2: cups, openEuler:20.03-LTS-SP4: cups, openEuler:22.03-LTS-SP3: cups, openEuler:22.03-LTS-SP4: cups, openEuler:24.03-LTS: cups, openEuler:24.03-LTS-SP1: cups&lt;/p&gt;
&lt;p&gt;CUPS is the standards-based, open source printing system developed by Apple Inc. for UNIX®-like operating systems. CUPS uses the Internet Printing Protocol (IPP) to support printing to local and network printers.&#13;
&#13;
Security Fix(es):&lt;/p&gt;
&lt;p&gt;[&amp;amp;apos;Hi all,\n\nthere is important security vulnerability in CUPS:\n\n\n\xa0\xa0 Description\n\n\n\xa0\xa0\xa0\xa0 Summary&amp;amp;apos;, &amp;amp;apos;Details&amp;amp;apos;, &amp;amp;apos;PoC\n\n- Configure CUPS with |DefaultAuthType Negotiate|.\n- Start CUPS&amp;amp;apos;, &amp;amp;apos;- cat /etc/cups/cupsd.conf\nhaha\n\n\n\xa0\xa0\xa0\xa0 Impact&amp;amp;apos;, &amp;amp;apos;Patch&amp;amp;apos;, &amp;amp;apos;Have a nice day,\n\n\nZdenek Dohnal\n\n--\nZdenek Dohnal\nSenior Software Engineer\nRed Hat, BRQ-TPBC&amp;amp;apos;](CVE-2025-58060)&lt;/p&gt;
&lt;p&gt;[&amp;amp;apos;Hi all!&amp;amp;apos;, &amp;amp;apos;Description\n\n\n\xa0\xa0\xa0\xa0 Summary&amp;amp;apos;, &amp;amp;apos;Details\n\nThe combination of:&amp;amp;apos;, &amp;amp;apos;Is shown in two places in OpenPrinting:\n\n|cups/scheduler/ipp.c libcupsfilters/cupsfilters/ipp.c |&amp;amp;apos;, &amp;amp;apos;PoC&amp;amp;apos;, &amp;amp;apos;Impact&amp;amp;apos;, &amp;amp;apos;Metrics:\n\n\n\xa0\xa0\xa0\xa0\xa0\xa0 CVSS v3 base metrics\n\nAttack vector Adjacent\nAttack complexity Low\nPrivileges required None\nUser interaction None\nScope Unchanged\nConfidentiality None\nIntegrity None\nAvailability High\n\nCredit -&amp;amp;apos;, &amp;amp;apos;Patch&amp;amp;apos;, &amp;amp;apos;Have a nice day!\n\n\nZdenek\n\n--\nZdenek Dohnal\nSenior Software Engineer\nRed Hat, BRQ-TPBC&amp;amp;apos;](CVE-2025-58364)&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/oesa-2025-2334</guid>
    </item>
    <item>
      <title>openSUSE-SU-2025:15562-1 — cups-2.4.14-1.1 on GA media</title>
      <link>https://cve.radiocsirt.org/vuln/opensuse-su-2025:15562-1</link>
      <description>&lt;p&gt;cups-2.4.14-1.1 on GA media&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cups-2.4.14-1.1 on GA media&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/opensuse-su-2025:15562-1</guid>
    </item>
    <item>
      <title>RHSA-2025:16590 — Red Hat Security Advisory: cups security update</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2025:16590</link>
      <description>&lt;p&gt;cups: Authentication Bypass in CUPS Authorization Handling cups: Null Pointer Dereference in CUPS ipp_read_io() Leading to Remote DoS&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;cups: Authentication Bypass in CUPS Authorization Handling cups: Null Pointer Dereference in CUPS ipp_read_io() Leading to Remote DoS&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2025:16590</guid>
    </item>
    <item>
      <title>SUSE-SU-2025:03178-1 — Security update for cups</title>
      <link>https://cve.radiocsirt.org/vuln/suse-su-2025:03178-1</link>
      <description>&lt;p&gt;Security update for cups&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Security update for cups&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/suse-su-2025:03178-1</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2025-58364</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58364</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: cups, Ubuntu:Pro:18.04:LTS: cups, Ubuntu:Pro:20.04:LTS: cups, Ubuntu:22.04:LTS: cups, Ubuntu:24.04:LTS: cups&lt;/p&gt;
&lt;p&gt;OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation of printer attributes causes null dereference in the libcups library. This is a remote DoS vulnerability available in local subnet in default configurations. It can cause the cups &amp;amp; cups-browsed to crash, on all the machines in local network who are listening for printers (so by default for all regular linux machines). On systems where the vulnerability CVE-2024-47176 (cups-filters 1.x/cups-browsed 2.x vulnerability) was not fixed, and the firewall on the machine does not reject incoming communication to IPP port, and the machine is set to be available to public internet, attack vector &amp;#34;Network&amp;#34; is possible. The current versions of CUPS and cups-browsed projects have the attack vector &amp;#34;Adjacent&amp;#34; in their default configurations. Version 2.4.13 contains a patch for CVE-2025-58364.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:Pro:16.04:LTS: cups, Ubuntu:Pro:18.04:LTS: cups, Ubuntu:Pro:20.04:LTS: cups, Ubuntu:22.04:LTS: cups, Ubuntu:24.04:LTS: cups&lt;/p&gt;
&lt;p&gt;OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation of printer attributes causes null dereference in the libcups library. This is a remote DoS vulnerability available in local subnet in default configurations. It can cause the cups &amp;amp; cups-browsed to crash, on all the machines in local network who are listening for printers (so by default for all regular linux machines). On systems where the vulnerability CVE-2024-47176 (cups-filters 1.x/cups-browsed 2.x vulnerability) was not fixed, and the firewall on the machine does not reject incoming communication to IPP port, and the machine is set to be available to public internet, attack vector &amp;#34;Network&amp;#34; is possible. The current versions of CUPS and cups-browsed projects have the attack vector &amp;#34;Adjacent&amp;#34; in their default configurations. Version 2.4.13 contains a patch for CVE-2025-58364.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-58364</guid>
    </item>
    <item>
      <title>WID-SEC-W-2025-2039 — CUPS: Mehrere Schwachstellen</title>
      <link>https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2039</link>
      <description>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CUPS ausnutzen, um Sicherheitsvorkehrungen zu umgehen und um einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Ein Angreifer kann mehrere Schwachstellen in CUPS ausnutzen, um Sicherheitsvorkehrungen zu umgehen und um einen Denial of Service Zustand herbeizuführen.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/wid-sec-w-2025-2039</guid>
    </item>
  </channel>
</rss>
