Release date:
2026-08-01 02:44:17 UTC
Description:
- CVE-2026-34978: reject ".." path traversal in the RSS notifier
notify-recipient-uri, both in notifier/rss.c and when the subscription
is created in the scheduler, and refuse to write when the target path
exists and is not a regular file; previously a remote IPP client could
make the lp-owned notifier clobber root-managed state such as
CacheDir/job.cache
- CVE-2026-34979: fix heap buffer overflow when building filter option
strings; ipp_length() skipped NOVALUE, MIMETYPE, NAMELANG, TEXTLANG,
URI and URISCHEME attributes that get_options() does emit, so the
allocated options buffer was undersized
Updated packages:
-
cups-2.3.3op2-16.el9_2.1.tuxcare.els13.x86_64.rpm
sha:ae53aa94465648c71e3bbb69790f540ba401f580a94ba4b34c0211469e9564dc
-
cups-client-2.3.3op2-16.el9_2.1.tuxcare.els13.x86_64.rpm
sha:76bd2af5756e92d6124a776e9644cf3bde9c0637216652cea63b990f93ef5839
-
cups-devel-2.3.3op2-16.el9_2.1.tuxcare.els13.i686.rpm
sha:b0ac50f3d9eecc3ba8b146fd8404765bbd2e16055888c1e036a48cfe36a09e5f
-
cups-devel-2.3.3op2-16.el9_2.1.tuxcare.els13.x86_64.rpm
sha:0aa4fcc2fa085a63a651ed341b184d341f843045a3cfeb5aef75010576695248
-
cups-filesystem-2.3.3op2-16.el9_2.1.tuxcare.els13.noarch.rpm
sha:b374cc047e0b1db85dbff4c402006ae51fb7e2169e47129a116f4243cbd12066
-
cups-ipptool-2.3.3op2-16.el9_2.1.tuxcare.els13.x86_64.rpm
sha:5954938bab6b4b40207fbb62af96673a7e3660dbc9328cde7cba2927234c8424
-
cups-libs-2.3.3op2-16.el9_2.1.tuxcare.els13.i686.rpm
sha:39dd52b535c7358591cd9a544f4f6fea9169d99b67db908d18376dda0dd235a2
-
cups-libs-2.3.3op2-16.el9_2.1.tuxcare.els13.x86_64.rpm
sha:888f987d45e1cf42435613a5c7d1de9698379263d2012a2ea7a9d21d49bf4dbe
-
cups-lpd-2.3.3op2-16.el9_2.1.tuxcare.els13.x86_64.rpm
sha:2724846cad7b1ae194f2badefc6cc11fa9be488034748c13bc4e7f1eb1481ba7
-
cups-printerapp-2.3.3op2-16.el9_2.1.tuxcare.els13.x86_64.rpm
sha:d7964271648fdef69a50cc1979241a5c1a18db8e29e96c1eef8ddf0ab3efc5b6
Notes:
This page is generated automatically and has not been checked for errors. For clarification or
corrections please contact the
CloudLinux Packaging Team.