{"id":"CVE-2026-107655","title":"A flaw was found in CUPS","summary":"A flaw was found in CUPS. When processing embedded job ticket comments within documents, the service improperly handles specific IPP attributes, causing an unhandled null pointer dereference. An unauthenticated attacker permitted to subm…","severity":"medium","cvss":4,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L","cwe":["CWE-476"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T18:17:02.200","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-107655","references":[{"url":"https://access.redhat.com/security/cve/CVE-2026-107655","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2548399","label":"secalert@redhat.com"},{"url":"https://github.com/OpenPrinting/cups/commit/12237ad","label":"secalert@redhat.com"},{"url":"https://github.com/OpenPrinting/cups/commit/25d6830","label":"secalert@redhat.com"},{"url":"https://github.com/OpenPrinting/cups/security/advisories/GHSA-58wv-9ffm-5w78","label":"secalert@redhat.com"},{"url":"https://github.com/OpenPrinting/cups/security/advisories/GHSA-58wv-9ffm-5w78","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"}],"tags":["nvd"],"epss":0.00128,"epssPercentile":0.02133,"ingestedAt":"2026-10-09T09:31:01.005Z","slug":"CVE-2026-107655","body":"## Overview\n\nA flaw was found in CUPS. When processing embedded job ticket comments within documents, the service improperly handles specific IPP attributes, causing an unhandled null pointer dereference. An unauthenticated attacker permitted to submit jobs to a shared printer queue can send a crafted Internet Printing Protocol (IPP) request to crash the print daemon, resulting in a temporary Denial of Service (DoS) for all printing services.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":22,"depthScoreParts":{"impact":22,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}