[CLSA-2026:1785836378] cups: Fix of 3 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-04 09:39:51 UTC
Description:
- CVE-2026-34978: reject ".." path traversal in the RSS notifier recipient URI - CVE-2026-34979: allocate enough memory for a job's options string to prevent heap-based buffer overflow - CVE-2026-34990: restrict local certificate authentication to domain socket connections and reject non-ipp device URIs for local printers
Updated packages:
  • cups-2.3.3op2-33.el9_6.1.tuxcare.els7.x86_64.rpm
    sha:4826e4724e6004eeec2fef0e1440f5efd2335f73dc55492e97b306d1471a9108
  • cups-client-2.3.3op2-33.el9_6.1.tuxcare.els7.x86_64.rpm
    sha:e739443c6988b9a55fccfa9f33c82712ee536b52ca3e70dba1a903048704c413
  • cups-devel-2.3.3op2-33.el9_6.1.tuxcare.els7.i686.rpm
    sha:8cda731f3deb03bb443603b0ced5d5fffa8a77c3b24faa9a1ed7c2ee6d46d06e
  • cups-devel-2.3.3op2-33.el9_6.1.tuxcare.els7.x86_64.rpm
    sha:4e5abb38006e98265102a2f65319f4c29da60271ba3c84f2e8cda8cdd4fa84e3
  • cups-filesystem-2.3.3op2-33.el9_6.1.tuxcare.els7.noarch.rpm
    sha:1e96c94d81cc1e818e6be69465e9c7720844c5f858d6ed5b18ede5468f460cfa
  • cups-ipptool-2.3.3op2-33.el9_6.1.tuxcare.els7.x86_64.rpm
    sha:e75f983e118b767f4c8cb27a4308dbbdc769c46cb3f5414693335e9e75074ce2
  • cups-libs-2.3.3op2-33.el9_6.1.tuxcare.els7.i686.rpm
    sha:80565b7fb7257fb9ffc1e6bc2d8b78ca6ca4c005d006f08dc505e9fc4c9fee43
  • cups-libs-2.3.3op2-33.el9_6.1.tuxcare.els7.x86_64.rpm
    sha:a9759b3839174a849deb47db9f4eadb9a18beb29536b647a8ff37c4c65c4c6e1
  • cups-lpd-2.3.3op2-33.el9_6.1.tuxcare.els7.x86_64.rpm
    sha:628ee70c41f4afbc1a3789f55212053519abd38401fa801d8dbc15af909a0bc9
  • cups-printerapp-2.3.3op2-33.el9_6.1.tuxcare.els7.x86_64.rpm
    sha:2153d8e0c94c2bc34881e4893df315abe23a0c48c34a96d67abd762d01f65329
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.