[CLSA-2026:1785510391] cups: Fix of 2 CVEs
Type:
security
Severity:
Moderate
Release date:
2026-08-01 05:23:36 UTC
Description:
- CVE-2021-25317: install /var/log/cups as 0700 root:sys instead of 0755 lp:sys so the 'lp' user cannot plant symlinks that cupsd follows on log creation. This matches the mode cupsd itself computes for the log directory (0300|LogFilePerm with --with-log-file-perm=0600). - CVE-2025-58364: already addressed by Patch103 (upstream e58cba9d), shipped in 1:1.6.3-52.tuxcare.els5; no code change in this release.
Updated packages:
  • cups-1.6.3-52.el7_9.tuxcare.els7.x86_64.rpm
    sha:eeac3ff86e4265ca2589d3fd07cac2c3a25d8ca8b4e4cb9c3ab89fe5bce2ebc8
  • cups-client-1.6.3-52.el7_9.tuxcare.els7.x86_64.rpm
    sha:4525d4df484419ced545ed208f2e37bad4ad1d6a06969280589d1fa41b2bc086
  • cups-devel-1.6.3-52.el7_9.tuxcare.els7.i686.rpm
    sha:966e863ad20741336bd4f03181c43c5221add6d08b5340226da24e0d978fd9c8
  • cups-devel-1.6.3-52.el7_9.tuxcare.els7.x86_64.rpm
    sha:a50bef889ed51643184612dd81e988d7c129965c40acbfbc01310cdff647f81a
  • cups-filesystem-1.6.3-52.el7_9.tuxcare.els7.noarch.rpm
    sha:fa49902e5451ccf38ad8be60937c094d9f24e425bb89382c97bcdf62125b4a88
  • cups-ipptool-1.6.3-52.el7_9.tuxcare.els7.x86_64.rpm
    sha:abb13ceb40a35e9d824298bca90954125e3ea24eeff1b7071354f18d062ad8a1
  • cups-libs-1.6.3-52.el7_9.tuxcare.els7.i686.rpm
    sha:adca5f510b42ac24bfbdac935139502ed0745580281edaabf670077a1863cbea
  • cups-libs-1.6.3-52.el7_9.tuxcare.els7.x86_64.rpm
    sha:a1b4a8970b5b4c1cf131c6415ca0b4b4e845f8b34b3b199e5f6bf221beafc972
  • cups-lpd-1.6.3-52.el7_9.tuxcare.els7.x86_64.rpm
    sha:7a6074704832b83b5daa2750bab5521c37b0e64e349177daa9f0a2fe0da52978
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.