| Name | CVE-2025-58436 |
| Description | OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a client that connects to cupsd but sends slow messages, e.g. only one byte per second, delays cupsd as a whole, such that it becomes unusable by other clients. This issue has been patched in version 2.4.15. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| cups (PTS) | bullseye | 2.3.3op2-3+deb11u8 | vulnerable |
| bullseye (security) | 2.3.3op2-3+deb11u10 | vulnerable | |
| bookworm | 2.4.2-3+deb12u8 | vulnerable | |
| bookworm (security) | 2.4.2-3+deb12u9 | vulnerable | |
| trixie | 2.4.10-3+deb13u2 | vulnerable | |
| trixie (security) | 2.4.10-3+deb13u1 | vulnerable | |
| forky | 2.4.14-1 | vulnerable | |
| sid | 2.4.15-1 | fixed |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| cups | source | (unstable) | 2.4.15-1 |
[trixie] - cups <no-dsa> (Minor issue)
[bookworm] - cups <no-dsa> (Minor issue)
[bullseye] - cups <postponed> (Minor issue)
https://www.openwall.com/lists/oss-security/2025/11/27/4
https://github.com/OpenPrinting/cups/security/advisories/GHSA-8wpw-vfgm-qrrr
Fixed by: https://github.com/OpenPrinting/cups/commit/40008d76a001babbb9beb9d9d74b01a86fb6ddb4 (master)
Fixed by: https://github.com/OpenPrinting/cups/commit/5d414f1f91bdca118413301b148f0b188eb1cdc6 (v2.4.15)