[CLSA-2026:1787145903] cups: Fix of CVE-2021-25317
Type:
security
Severity:
Low
Release date:
2026-08-19 13:25:14 UTC
Description:
- CVE-2021-25317: ship /var/log/cups owned by root:lp instead of lp:sys so a local lp user can no longer plant a symlink in the log directory and make the root cupsd create arbitrary root-owned files, matching current RHEL 9 packaging
CVEs fixed:
Updated packages:
  • cups-2.3.3op2-16.el9_2.1.tuxcare.els15.x86_64.rpm
    sha:dc1ba933e5865b86a837ee744286111393b1ed9758b2a3c523790820f3188d4b
  • cups-client-2.3.3op2-16.el9_2.1.tuxcare.els15.x86_64.rpm
    sha:b5576aeccf97a6f444d65544b74f50730a4bf583e857e04e077f2f315a829dbe
  • cups-devel-2.3.3op2-16.el9_2.1.tuxcare.els15.i686.rpm
    sha:d6ae00c34c48d63c3ad4528d7077245a8a2200df2f6f0ffecf61b01a0d10460c
  • cups-devel-2.3.3op2-16.el9_2.1.tuxcare.els15.x86_64.rpm
    sha:06ee3885efbbd4eaa45c43d2b06a143573eb805315aa22b99835e40cfd947dae
  • cups-filesystem-2.3.3op2-16.el9_2.1.tuxcare.els15.noarch.rpm
    sha:36197e5172dfdd1e64a4aba338e59445c3be97a00b42db303e49bf8a90e173c6
  • cups-ipptool-2.3.3op2-16.el9_2.1.tuxcare.els15.x86_64.rpm
    sha:873c18b6f7eda62e46360a18c794f3cdd285c3f488a73d398cdca427b1faa7f9
  • cups-libs-2.3.3op2-16.el9_2.1.tuxcare.els15.i686.rpm
    sha:3b64427c894a42ab90eee8561cbc6ef702af425cb24ad70125d95f3982386502
  • cups-libs-2.3.3op2-16.el9_2.1.tuxcare.els15.x86_64.rpm
    sha:462f03e2662f742b8c177e77ff5a0d4f9a089b1ae22baac770253add9ca37077
  • cups-lpd-2.3.3op2-16.el9_2.1.tuxcare.els15.x86_64.rpm
    sha:0463dde0cdd34e43aed4a110485842831d0b9a5a77b13872981516c8597d5f73
  • cups-printerapp-2.3.3op2-16.el9_2.1.tuxcare.els15.x86_64.rpm
    sha:d6791a0c8d50bb70a7b539b9aa54f61a9a7defca4e3abffc34d3b406e2345b36
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.