USN-8578-1: CUPS control character injection vulnerability
It was discovered that CUPS did not properly filter control characters in IPP string attributes and PPD keywords. An unauthenticated attacker could exploit this to execute arbitrary code as the lp user on systems with shared target queues.
CSIRTS triage
- What
- CUPS did not properly filter control characters, allowing an unauthenticated attacker to execute arbitrary code.
- Who is affected
- All installations of CUPS are potentially affected.
- Urgency
- Remediation is necessary due to the potential for exploitation.
- Action
- Update CUPS to the latest version.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CUPS
Get an email when a new CUPS advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://ubuntu.com/security/notices/USN-8578-1
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-349800.50% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 40% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-34980 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- medium[UPDATE] [medium] CUPS: Multiple Vulnerabilitiescert-bund
More from Ubuntu Security Notices
- highUSN-8620-4: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- highUSN-8620-3: Linux kernel (Intel IoTG) vulnerabilities2026-07-31
- unknownUSN-8625-1: OpenSSL vulnerability2026-07-30
- unknownUSN-8624-1: Sinatra vulnerability2026-07-29
- unknownUSN-8623-1: Linux kernel (NVIDIA) vulnerabilities2026-07-29