gpp_maybe Security update for cups
SUSE-SL-Micro-6.2-802


This update for cups fixes the following issues - CVE-2026-27447: Authorization bypass via case-insensitive group-member lookup (bsc#1261572). - CVE-2026-34978: Path traversal in RSS notify-recipient-uri enables file write outside CacheDir/rss (bsc#1261571). - CVE-2026-34979: Heap overflow in `get_options()` (bsc#1261570). - CVE-2026-34980: Shared PostScript queue lets anonymous Print-Job requests reach `lp` code execution over the network (bsc#1261569). - CVE-2026-34990: Local print admin token disclosure using temporary printers (bsc#1261568). - CVE-2026-39314: negative `job-password-supported` attribute can lead to a denial of service (bsc#1261743). - CVE-2026-39316: dangling subscription pointer can lead to a denial of service (bsc#1261742). - CVE-2026-41079: crafted SNMP response can lead to stack-based out-of-bounds read and sensitive memory disclosure (bsc#1263116). Changes for cups: - Version upgrade to 2.4.19. - Version upgrade to 2.4.18. - Version upgrade to 2.4.17: * The scheduler followed symbolic links when cleaning out its temporary directory (Issue #1448) * Updated `cupsFileGetConf` and `cupsFilePutConf` to escape more characters. * Updated man page `cancel` (Issue #984) * Updated `cupsRasterReadHeader` to validate more of the page header values (Issue #1501) * Fixed an issue with the class/printer CGI name checking. * Fixed infinite loop in `http_write()` on busy print servers (Issue #827) * Fixed potential TLS blocking issues (Issue #1128) * Fixed a job history bug in the scheduler (Issue #1440) * Fixed notifier logging bug that would result in nul bytes getting into the log (Issue #1450) * Fixed possible use-after-free in `cupsdReadClient()` (Issue #1454) * Fixed a document format bug in the IPP backend (Issue #1457) * Fixed DRAIN_OUTPUT race condition (Issue #1461) * Fixed a bug when then `ippFindXxx` and `ippSetXxx` functions were mixed. * Fixed the mapping of supply type keywords to SNMP names. * Fixed a bug in the IPP backend when SNMP was disabled. * Fixed a crash bug in the rastertoepson filter. * Fixed a bug in cgiCheckVariables. * Fixed handling read/write errors with OpenSSL (Issue #1506) * Fixed handling rehandshake error in `_httpTLSRead` (Issue #1508) * Fixed a debug printf bug on Windows (Issue #1529) * Fixed a recursion issue with encoding of nested collections (Issue #1539) * Fixed parsing of the `LimitRequestBody`, `MaxLogSize`, and `MaxRequestSize` directives in "cupsd.conf" (Issue #1540) * Fixed a parsing bug in `ipptool` (Issue #1542) * Fixed blank line detection in the `rastertolabel` filter (Issue #1545) * Fixed `httpPeek` edge case on compressed streams


cloud_download Downloads

SUSE Linux Micro 6.2 s390x
  • Packages
    cups-config
    CUPS library configuration files
    2.4.19-160000.1.1 lock rpm
    libcups2
    HTTP/IPP communication and printer queue and job library
    2.4.19-160000.1.1 lock rpm
SUSE Linux Micro 6.2 ppc64le
  • Packages
    cups-config
    CUPS library configuration files
    2.4.19-160000.1.1 lock rpm
    libcups2
    HTTP/IPP communication and printer queue and job library
    2.4.19-160000.1.1 lock rpm
SUSE Linux Micro 6.2 aarch64
  • Packages
    cups-config
    CUPS library configuration files
    2.4.19-160000.1.1 lock rpm
    libcups2
    HTTP/IPP communication and printer queue and job library
    2.4.19-160000.1.1 lock rpm
SUSE Linux Micro 6.2 x86_64
  • Packages
    cups-config
    CUPS library configuration files
    2.4.19-160000.1.1 lock rpm
    libcups2
    HTTP/IPP communication and printer queue and job library
    2.4.19-160000.1.1 lock rpm