CVE-2025-58436
published 2025-11-29CVE-2025-58436: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd…
PriorityP422medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.19%
9.4th percentile
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue has been patched in version 2.4.15.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 2.4.15-1 | 2.4.15-1 |
| apple | cups | >= 0 < 2.4.1op1-1ubuntu4.16 | 2.4.1op1-1ubuntu4.16 |
| apple | cups | >= 0 < 2.4.7-1.2ubuntu7.9 | 2.4.7-1.2ubuntu7.9 |
| apple | cups | >= 0 < 2.4.12-0ubuntu3.5 | 2.4.12-0ubuntu3.5 |
| apple | cups | >= 0 < 2.1.3-4ubuntu0.11+esm12 | 2.1.3-4ubuntu0.11+esm12 |
| apple | cups | >= 0 < 2.2.7-1ubuntu2.10+esm10 | 2.2.7-1ubuntu2.10+esm10 |
| apple | cups | >= 0 < 2.3.1-9ubuntu1.9+esm4 | 2.3.1-9ubuntu1.9+esm4 |
| debian | cups | < cups 2.4.15-1 (forky) | cups 2.4.15-1 (forky) |
| msrc | azl3_cups_2.4.13-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_cups_2.4.16-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cups_2.3.3op2-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_cups_2.3.3op2-11_on_cbl_mariner_2.0 | — | — |
| openprinting | cups | < 2.4.15 | 2.4.15 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vendor_debian5.1MEDIUM
vendor_msrc5.1MEDIUM
vendor_redhat5.1MEDIUM
vendor_ubuntu5.1MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
CUPS vulnerability
vendor_ubuntu·2025-12-04·CVSS 5.1
CVE-2025-58436 [MEDIUM] CUPS vulnerability
Title: CUPS vulnerability
Summary: CUPS could be made to stop responding if it received specially crafted
network traffic.
USN-7912-1 fixed vulnerabilities in CUPS. This update provides the
corresponding update for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS.
Original advisory details:
Johannes Meixner and Paul Zirnik discovered that CUPS incorrectly handled
clients that send messages slowly. A remote attacker could possibly use
this issue to cause CUPS to stop responding, resulting in a denial of
service. (CVE-2025-58436)
In addition, this update fixes a regression introduced in USN-7897-1 which
resulted in certain invalid configuration file directives to cause the
CUPS daemon to fail to start.
Instructions: In general, a standard system update will make all the necessa
Ubuntu
CUPS vulnerability
vendor_ubuntu·2025-12-04·CVSS 5.1
CVE-2025-58436 [MEDIUM] CUPS vulnerability
Title: CUPS vulnerability
Summary: CUPS could be made to stop responding if it received specially crafted
network traffic.
Johannes Meixner and Paul Zirnik discovered that CUPS incorrectly handled
clients that send messages slowly. A remote attacker could possibly use
this issue to cause CUPS to stop responding, resulting in a denial of
service. (CVE-2025-58436)
In addition, this update fixes a regression introduced in USN-7897-1 which
resulted in certain invalid configuration file directives to cause the CUPS
daemon to fail to start.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
cups: Slow client communication leads to a possible DoS attack
vendor_redhat·2025-12-01·CVSS 5.1
CVE-2025-58436 [MEDIUM] CWE-412 cups: Slow client communication leads to a possible DoS attack
cups: Slow client communication leads to a possible DoS attack
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue has been patched in version 2.4.15.
A flaw was found in cups. A client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable
by other clients.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread
Microsoft
OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack
vendor_msrc·2025-11-11·CVSS 5.1
CVE-2025-58436 [MEDIUM] CWE-400 OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack
OpenPrinting CUPS slow client can halt cupsd, leading to a possible DoS attack
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2025-58436: cups - OpenPrinting CUPS is an open source printing system for Linux and other Unix-lik...
vendor_debian·2025·CVSS 5.1
CVE-2025-58436 [MEDIUM] CVE-2025-58436: cups - OpenPrinting CUPS is an open source printing system for Linux and other Unix-lik...
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue has been patched in version 2.4.15.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.4.15-1)
sid: resolved (fixed in 2.4.15-1)
trixie: open
OSV
cups vulnerability
osv·2025-12-04·CVSS 5.5
CVE-2025-58436 [MEDIUM] cups vulnerability
cups vulnerability
Johannes Meixner and Paul Zirnik discovered that CUPS incorrectly handled
clients that send messages slowly. A remote attacker could possibly use
this issue to cause CUPS to stop responding, resulting in a denial of
service. (CVE-2025-58436)
In addition, this update fixes a regression introduced in USN-7897-1 which
resulted in certain invalid configuration file directives to cause the CUPS
daemon to fail to start.
OSV
cups vulnerability
osv·2025-12-04·CVSS 5.5
CVE-2025-58436 [MEDIUM] cups vulnerability
cups vulnerability
USN-7912-1 fixed vulnerabilities in CUPS. This update provides the
corresponding update for Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, and Ubuntu
20.04 LTS.
Original advisory details:
Johannes Meixner and Paul Zirnik discovered that CUPS incorrectly handled
clients that send messages slowly. A remote attacker could possibly use
this issue to cause CUPS to stop responding, resulting in a denial of
service. (CVE-2025-58436)
In addition, this update fixes a regression introduced in USN-7897-1 which
resulted in certain invalid configuration file directives to cause the
CUPS daemon to fail to start.
OSV
CVE-2025-58436: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems
osv·2025-11-29·CVSS 5.5
CVE-2025-58436 [MEDIUM] CVE-2025-58436: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue has been patched in version 2.4.15.
No detection rules found.
No public exploits indexed.
https://github.com/OpenPrinting/cups/commit/40008d76a001babbb9beb9d9d74b01a86fb6ddb4https://github.com/OpenPrinting/cups/releases/tag/v2.4.15https://github.com/OpenPrinting/cups/security/advisories/GHSA-8wpw-vfgm-qrrrhttp://www.openwall.com/lists/oss-security/2025/11/27/4https://github.com/OpenPrinting/cups/security/advisories/GHSA-8wpw-vfgm-qrrr
2025-11-29
Published