CVE-2025-61915: medium-severity vulnerability in OpenPrinting cups
OpenPrinting CUPS vulnerable to stack based out-of-bound write
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
A user with printer admin rights can trick the CUPS printing system into writing data outside safe memory boundaries by submitting a malicious configuration through the web interface. This can allow attackers to crash the system or potentially execute code with root privileges.
CWE-124 and CWE-129 stack-based buffer overflow vulnerabilities exist in CUPS configuration parsing prior to v2.4.15. An authenticated attacker in the lpadmin group can inject a crafted configuration line via the web UI that causes the root-privileged cupsd process to write beyond allocated stack memory during parsing, enabling denial of service or privilege escalation.
In the same product, most dangerous first.