CVE-2025-61915
published 2025-11-29CVE-2025-61915: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can…
PriorityP434medium6.7CVSS 3.1
AVLACLPRHUINSUCHIHAH
EPSS
0.41%
33.1th percentile
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | cups | >= 0 < 2.4.15-1 | 2.4.15-1 |
| debian | cups | < cups 2.4.15-1 (forky) | cups 2.4.15-1 (forky) |
| msrc | azl3_cups_2.4.13-1_on_azure_linux_3.0 | — | — |
| msrc | cbl2_cups_2.3.3op2-10_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_cups_2.3.3op2-11_on_cbl_mariner_2.0 | — | — |
| openprinting | cups | < 2.4.15 | 2.4.15 |
CVSS provenance
nvdv3.16.7MEDIUMCVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
osv6.7MEDIUM
vendor_debian6.0MEDIUM
vendor_msrc6.0MEDIUM
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
CVE-2025-61915: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems
osv·2025-11-29·CVSS 6.7
CVE-2025-61915 [MEDIUM] CVE-2025-61915: OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.
Red Hat
CUPS: Local denial-of-service via cupsd.conf update and related issues
vendor_redhat·2025-11-28·CVSS 6.0
CVE-2025-61915 [MEDIUM] CWE-1173 CUPS: Local denial-of-service via cupsd.conf update and related issues
CUPS: Local denial-of-service via cupsd.conf update and related issues
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.
A flaw was found in cups. A user in group defined by SystemGroup directive in /etc/cups/cups-files.conf can use the cups web ui to change the config
and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write.
Statement: The highest threat of this flaw is to system availability. A
Ubuntu
CUPS vulnerability
vendor_ubuntu·2025-11-27
CVE-2025-61915 CUPS vulnerability
Title: CUPS vulnerability
Summary: CUPS could be made to crash or run programs as an administrator if it
opened a specially crafted file.
It was discovered that CUPS incorrectly handled input from users in the web
configuration settings. An attacker could use this issue to insert
malicious configuration options, causing a denial of service or possibly
executing arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
OpenPrinting CUPS vulnerable to stack based out-of-bound write
vendor_msrc·2025-11-11·CVSS 6.0
CVE-2025-61915 [MEDIUM] CWE-129 OpenPrinting CUPS vulnerable to stack based out-of-bound write
OpenPrinting CUPS vulnerable to stack based out-of-bound write
Mariner: Mariner
GitHub_M: GitHub_M
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microsoft.com/en-us/azure/azure-linux/tutorial-azure-linux-upgrade
Debian
CVE-2025-61915: cups - OpenPrinting CUPS is an open source printing system for Linux and other Unix-lik...
vendor_debian·2025·CVSS 6.0
CVE-2025-61915 [MEDIUM] CVE-2025-61915: cups - OpenPrinting CUPS is an open source printing system for Linux and other Unix-lik...
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.4.15-1)
sid: resolved (fixed in 2.4.15-1)
trixie: open
No detection rules found.
No public exploits indexed.
https://github.com/OpenPrinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0https://github.com/OpenPrinting/cups/releases/tag/v2.4.15https://github.com/OpenPrinting/cups/security/advisories/GHSA-hxm8-vfpq-jrfchttp://www.openwall.com/lists/oss-security/2025/11/27/5https://github.com/OpenPrinting/cups/security/advisories/GHSA-hxm8-vfpq-jrfc
2025-11-29
Published