[CLSA-2026:1786675343] cups: Fix of CVE-2026-34990
Type:
security
Severity:
Moderate
Release date:
2026-08-14 02:42:34 UTC
Description:
- CVE-2026-34990: restrict local certificate authentication to AF_LOCAL domain socket connections instead of any loopback address, limit CUPS-Create-Local-Printer to ipp:/ipps: device URIs, and require FileDevice plus an already existing file (no O_CREAT/O_TRUNC) for file: output; previously a local unprivileged user could coerce cupsd into authenticating to an IPP service on 127.0.0.1, reuse the harvested "Authorization: Local" token to drive /admin/ requests, persist a file:/// print queue and thereby overwrite arbitrary files as root
CVEs fixed:
Updated packages:
  • cups-2.3.3op2-16.el9_2.1.tuxcare.els14.x86_64.rpm
    sha:178d6e39cec4bcb858aa392177c2269de9f92c4ffd27f5002ce681f8751ca488
  • cups-client-2.3.3op2-16.el9_2.1.tuxcare.els14.x86_64.rpm
    sha:62fd450841d90cee58347c8c62cc4e3d4bcad670c578d899ffb29ddaef9661c2
  • cups-devel-2.3.3op2-16.el9_2.1.tuxcare.els14.i686.rpm
    sha:3b4887feda712ab8255e31a04c3926520e931df9426d436fd9fe95262f728261
  • cups-devel-2.3.3op2-16.el9_2.1.tuxcare.els14.x86_64.rpm
    sha:e4cab7bf0395edb3ce1854037a0046a79a262b70219e1eb5fb412802c83d8a7b
  • cups-filesystem-2.3.3op2-16.el9_2.1.tuxcare.els14.noarch.rpm
    sha:1ad7460a6bc167ef8f41f3f4ea5ee75f13d1cd4e019ff1ad1f7acd9b940904e9
  • cups-ipptool-2.3.3op2-16.el9_2.1.tuxcare.els14.x86_64.rpm
    sha:264c3197b5cc7ebe38c4c23cead430ed2ea7dd0f0e5d0a9a6f8e565146d4676b
  • cups-libs-2.3.3op2-16.el9_2.1.tuxcare.els14.i686.rpm
    sha:af45c6199dd35ff28848897911d9f00d8f51597cc21543794d9383de5735ce03
  • cups-libs-2.3.3op2-16.el9_2.1.tuxcare.els14.x86_64.rpm
    sha:bb6ef62927e9296d759416191ccbece1eaeb98bebbb9c7386ccab0ecddfa2416
  • cups-lpd-2.3.3op2-16.el9_2.1.tuxcare.els14.x86_64.rpm
    sha:8c9bef8301a70d60ce5cf0294da885c5d80e6d6f93bbf1eebb362d2bd3aa61ff
  • cups-printerapp-2.3.3op2-16.el9_2.1.tuxcare.els14.x86_64.rpm
    sha:865dfa4316625dd62d619a3f2fa304d1ba6449569d7b5f26f0cf0b7d18bfaf65
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.