#1147521 cups: CVE-2026-87875 CVE-2026-87876

Package:
src:cups
Source:
src:cups
Submitter:
Salvatore Bonaccorso
Date:
2026-09-12 15:21:02 UTC
Severity:
normal
Tags:
#1147521#5
Date:
2026-09-12 15:19:56 UTC
From:
To:
Hi,

The following vulnerabilities were published for cups.

CVE-2026-87875[0]:
| The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a
| source-length bound and can read past the end of the source buffer,
| resulting in a heap out-of-bounds read. This is reachable via SNMP
| supply-description parsing in backend/snmp-supplies.c with attacker-
| controlled content.


CVE-2026-87876[1]:
| Two case-insensitive comparisons on request-derived usernames
| outside the main authorization path in CUPS's scheduler (printer ACL
| validation and private-attribute filtering) could allow bypass of
| username-based access controls in certain configurations.

The security tracker references list as well the GHSAs for those
issues.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-87875
https://www.cve.org/CVERecord?id=CVE-2026-87875
[1] https://security-tracker.debian.org/tracker/CVE-2026-87876
https://www.cve.org/CVERecord?id=CVE-2026-87876

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore