#1147248 cups: 1 unresolved CVE in Debian Trixie (1 High)

Package:
cups
Source:
cups
Description:
Common UNIX Printing System(tm) - PPD/driver support, web interface
Submitter:
Samonte, Joshua
Date:
2026-09-10 17:13:01 UTC
Severity:
normal
Tags:
#1147248#5
Date:
2026-09-10 03:16:50 UTC
From:
To:
Hi Team,

I am reporting an unresolved CVE affecting the cups source package (specifically libcups2t64) on Debian Trixie (Debian 13), identified via a Prisma scanner.


  *   CVE-2026-34980 (High)

Notes:
While this vulnerability strictly requires the network-exposed cupsd daemon (which we have removed), the library binary libcups2t64 remains flagged by container image scanners. This client library is required as a dependency for chromium and cannot be removed.

This issue is fixed upstream in cups v2.4.17. Could you please advise on when a patched version will be introduced to Trixie?


Regards,
Joshua Aldwin L. Samonte
Software Prod & Plat Eng Specialist
Advanced Technology Centers in the Philippines
*: joshua.a.samonte@accenture.com<mailto:joshua.a.samonte@accenture.com>

#1147248#10
Date:
2026-09-10 15:21:24 UTC
From:
To:
People at Accenture, stop wasting our time. Please read
https://www.debian.org/security/faq#cve-severity-assessment

Regards,
Salvatore

#1147248#21
Date:
2026-09-10 17:08:18 UTC
From:
To:
Hi,

please update your Prisma scanner or use a software that is not broken.
According to [1] the CVSS Version 4.0 score of this CVE is 6.1, which is
"just" medium. This score was evaluated by upstream and should be the
most correct one.

Thanks for this note, which makes things more clear. As the CVE is only
related to the job scheduler, which is only used in the server, the
library is not affected at all by this CVE. So it is really your scanner
that is broken. In order to minimize such false positives, I suggest to
use some working software.

This question causes some astonishment on my side. Is there anything you
have done to support Debian lately? Maybe I looked at the wrong places,
but I found nothing. Do you really expect an answer other than "It is
done when it is done."?

   Thorsten


[1] https://nvd.nist.gov/vuln/detail/cve-2026-34980