USN-7897-1: CUPS vulnerability
USN-7897-1: CUPS vulnerability
Publication date: 27 November 2025
Overview: CUPS could be made to crash or run programs as an administrator if it opened a specially crafted file.
Packages
- cups - Common UNIX Printing System(tm)
Details
It was discovered that CUPS incorrectly handled input from users in the web
configuration settings. An attacker could use this issue to insert
malicious configuration options, causing a denial of service or possibly
executing arbitrary code.
Update instructions
In general, a standard system update will make all the necessary changes.
25.10 questing
- cups – 2.4.12-0ubuntu3.3
- cups-daemon – 2.4.12-0ubuntu3.3
25.04 plucky cup
– 2.4.12-0ubuntu1.4
- cups-daemon – 2.4.12-0ubuntu1.4
24.04 LTS noble
- cups – 2.4.7-1.2ubuntu7.7
- cups-daemon – 2.4.7-1.2ubuntu7.7
22.04 LTS jammy
- cups – 2.4.1op1-1ubuntu4.15
- cups-daemon – 2.4.1op1-1ubuntu4.15
20.04 LTS focal
- cups – 2.3.1-9ubuntu1.9+esm3
- cups-daemon – 2.3.1-9ubuntu1.9+esm3
18.04 LTS bionic
- cups – 2.2.7-1ubuntu2.10+esm9
- cups-daemon – 2.2.7-1ubuntu2.10+esm9
16.04 LTS
xenial cups – 2.1.3-4ubuntu0.11+esm11
- cups-daemon – 2.1.3-4ubuntu0.11+esm11

