Hi Team, I am reporting an unresolved CVE affecting the cups source package (specifically libcups2t64) on Debian Trixie (Debian 13), identified via a Prisma scanner. * CVE-2026-34980 (High) Notes: While this vulnerability strictly requires the network-exposed cupsd daemon (which we have removed), the library binary libcups2t64 remains flagged by container image scanners. This client library is required as a dependency for chromium and cannot be removed. This issue is fixed upstream in cups v2.4.17. Could you please advise on when a patched version will be introduced to Trixie? Regards, Joshua Aldwin L. Samonte Software Prod & Plat Eng Specialist Advanced Technology Centers in the Philippines *: joshua.a.samonte@accenture.com<mailto:joshua.a.samonte@accenture.com>
People at Accenture, stop wasting our time. Please read https://www.debian.org/security/faq#cve-severity-assessment Regards, Salvatore
Hi, please update your Prisma scanner or use a software that is not broken. According to [1] the CVSS Version 4.0 score of this CVE is 6.1, which is "just" medium. This score was evaluated by upstream and should be the most correct one. Thanks for this note, which makes things more clear. As the CVE is only related to the job scheduler, which is only used in the server, the library is not affected at all by this CVE. So it is really your scanner that is broken. In order to minimize such false positives, I suggest to use some working software. This question causes some astonishment on my side. Is there anything you have done to support Debian lately? Maybe I looked at the wrong places, but I found nothing. Do you really expect an answer other than "It is done when it is done."? Thorsten [1] https://nvd.nist.gov/vuln/detail/cve-2026-34980