OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create refers to a temporary printer that has been automatically deleted. Temporary-printer cleanup can remove the destination without canceling its held jobs, and the scheduler dereferences the NULL result of cupsdFindDest() while checking holding_new_jobs. This terminates cupsd and interrupts all queues managed by that process. In some plausible scenarios, an unprivileged submission can trigger this.

Project Subscriptions

Vendors Products
Openprinting Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Fri, 09 Oct 2026 04:30:00 +0000

Type Values Removed Values Added
Description OpenPrinting CUPS before 2.4.20 contains a NULL pointer dereference in cupsdCheckJobs() when a job marked job-held-on-create refers to a temporary printer that has been automatically deleted. Temporary-printer cleanup can remove the destination without canceling its held jobs, and the scheduler dereferences the NULL result of cupsdFindDest() while checking holding_new_jobs. This terminates cupsd and interrupts all queues managed by that process. In some plausible scenarios, an unprivileged submission can trigger this.
First Time appeared Openprinting
Openprinting cups
Weaknesses CWE-476
CPEs cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*
Vendors & Products Openprinting
Openprinting cups
References
Metrics cvssV3_1

{'score': 5.1, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-09T04:06:55.424Z

Reserved: 2026-10-09T04:06:54.629Z

Link: CVE-2026-107888

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-09T05:16:44.407

Modified: 2026-10-09T05:16:44.407

Link: CVE-2026-107888

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses