[CLSA-2026:1788967622] Fix CVE(s): CVE-2026-34980
Type:
security
Severity:
Important
Release date:
2026-09-09 15:27:13 UTC
Description:
* SECURITY UPDATE: filter control characters from option values in the scheduler to prevent PPD keyword injection via Print-Job. - debian/patches/CVE-2026-34980.patch: filter out control characters from IPP option values in scheduler/job.c and allowlist-filter special PPD keywords in the CUPSD_LOG_PPD branch of update_job(); includes the upstream follow-ups for Issue #1532 (get_options() no longer loops forever on a value holding whitespace or a dropped control character), Issue #1562 (the allowlist advances its keyword pointer instead of testing keywords[0] repeatedly), Issue #1630 (whitespace stays backslash-escaped, so cupsParseOptions() in the filters no longer truncates option values containing spaces) and the case-insensitive keyword comparison that closes a "cupsfilter2" spelling bypass of the allowlist. - CVE-2026-34980. * Make the package testable on the ELS build nodes. None of these three changes is a CVE fix; the two patches are also carried by tuxcare-current/debian10els. - debian/patches/maxfds-limit.patch: cap MaxFDs at 65535 in scheduler/main.c, backported from upstream Issue #989 (beb84401c6698dfe937178d8ac8fa38505468dbb), so cupsd stops aborting at startup with "cupsdDoSelect() failed - Bad address!" on hosts whose RLIMIT_NOFILE hard limit is very large but not RLIM_INFINITY. - debian/patches/waiting-limit.patch: bound the "waiting for the scheduler" loop in test/run-stp-tests.sh at 60 seconds and take the test user from "id -un", so a scheduler that will not start fails the build with a diagnostic instead of hanging until the build system's 12 hour task limit. - debian/rules: hand test/run-stp-tests.sh a free TCP port instead of letting its cupsd default to 8631. CUPS_TESTBASE already keeps the config, spool, logs and domain socket of a run private, but pbuilder chroots share the host network namespace, so two cups builds on one node used to fight over that one port -- the second scheduler could not bind, the first answered its "lpstat -r" anyway, and both suites then drove a single cupsd, inflating every absolute count in the test summary.
CVEs fixed:
Updated packages:
  • cups_2.3.3op2-3+deb11u10+tuxcare.els1_amd64.deb
    sha:fbb9ba354235b9f04ecc8692de2ba59443c0eb03
  • cups-bsd_2.3.3op2-3+deb11u10+tuxcare.els1_amd64.deb
    sha:08f9d5a8be12c15a606a40cbb69cd9f009345be2
  • cups-client_2.3.3op2-3+deb11u10+tuxcare.els1_amd64.deb
    sha:be98f84e6f37f15ca61e5010866cd93efa79e82c
  • cups-common_2.3.3op2-3+deb11u10+tuxcare.els1_all.deb
    sha:1ccd52e6107c771fad929dcfaca9da038559b845
  • cups-core-drivers_2.3.3op2-3+deb11u10+tuxcare.els1_amd64.deb
    sha:cc3bb0eee972bac947093ee9f0a37ceb2c191995
  • cups-daemon_2.3.3op2-3+deb11u10+tuxcare.els1_amd64.deb
    sha:b9234314cd12d52a9720532a2fe1857d4c34d76a
  • cups-ipp-utils_2.3.3op2-3+deb11u10+tuxcare.els1_amd64.deb
    sha:0046fde6d12b2db6a3f75bd3324b08ad5baf9f55
  • cups-ppdc_2.3.3op2-3+deb11u10+tuxcare.els1_amd64.deb
    sha:d35001926afb4d0ff19fa00b3e52957853936376
  • cups-server-common_2.3.3op2-3+deb11u10+tuxcare.els1_all.deb
    sha:bc5991eea59c325b8640e466efe2f35a567d5034
  • libcups2_2.3.3op2-3+deb11u10+tuxcare.els1_amd64.deb
    sha:901ad7dba8882d68a616c581e9db4a1a5c04e2ed
  • libcups2-dev_2.3.3op2-3+deb11u10+tuxcare.els1_amd64.deb
    sha:5141f30ed894020698a89975dfc9f87085b347d2
  • libcupsimage2_2.3.3op2-3+deb11u10+tuxcare.els1_amd64.deb
    sha:2ae44de73f854e8edeac8f882bba838d0f1aaa57
  • libcupsimage2-dev_2.3.3op2-3+deb11u10+tuxcare.els1_amd64.deb
    sha:a97985b4afca62358565dce80d007df7aef8aae4
  • cups_2.3.3op2-3+deb11u10+tuxcare.els1_arm64.deb
    sha:0e0884123582b3edca2038d4ece19fcb350d61be
  • cups-bsd_2.3.3op2-3+deb11u10+tuxcare.els1_arm64.deb
    sha:b1202905d852d7e3f396190e9fe0ab8fdb1222b8
  • cups-client_2.3.3op2-3+deb11u10+tuxcare.els1_arm64.deb
    sha:2ad5eac3ab0e1298a6b72c60c1c9fc524e356237
  • cups-core-drivers_2.3.3op2-3+deb11u10+tuxcare.els1_arm64.deb
    sha:08dd0f20bc4d3747b394b2a9c6d263f764b6e427
  • cups-daemon_2.3.3op2-3+deb11u10+tuxcare.els1_arm64.deb
    sha:9348217cc2abcb9e19e3197b312f0162865b2c5a
  • cups-ipp-utils_2.3.3op2-3+deb11u10+tuxcare.els1_arm64.deb
    sha:c31519d95e0f30a198b962f64b80493818ec1bc7
  • cups-ppdc_2.3.3op2-3+deb11u10+tuxcare.els1_arm64.deb
    sha:e395cc46fc3a626ac3ecaed1a3388e87eef23e03
  • libcups2_2.3.3op2-3+deb11u10+tuxcare.els1_arm64.deb
    sha:d93dc079f746caf3eb8882069c9174df3c051feb
  • libcups2-dev_2.3.3op2-3+deb11u10+tuxcare.els1_arm64.deb
    sha:13770f7dc50800e9c34fc8c6526234e57e664228
  • libcupsimage2_2.3.3op2-3+deb11u10+tuxcare.els1_arm64.deb
    sha:0eb3c69bf308e88254c94df7de153cfb4e37a6b1
  • libcupsimage2-dev_2.3.3op2-3+deb11u10+tuxcare.els1_arm64.deb
    sha:543280c711e117e739f719481f4d3dd65fb0dfa4
  • cups_2.3.3op2-3+deb11u10+tuxcare.els1_armel.deb
    sha:838ac9f8b7e2a7e7d14464d551508c561e9ab7ee
  • cups-bsd_2.3.3op2-3+deb11u10+tuxcare.els1_armel.deb
    sha:cae5114aaea01a807146629f751995435813a2e5
  • cups-client_2.3.3op2-3+deb11u10+tuxcare.els1_armel.deb
    sha:56c8832b0f9defaccb3431c8cc75d1f42b8921d9
  • cups-core-drivers_2.3.3op2-3+deb11u10+tuxcare.els1_armel.deb
    sha:6ec54b30c122e68bd280873c4ca883105a9e5676
  • cups-daemon_2.3.3op2-3+deb11u10+tuxcare.els1_armel.deb
    sha:34d16e9c7782dd3ee23657be2e7e09a2c6247d17
  • cups-ipp-utils_2.3.3op2-3+deb11u10+tuxcare.els1_armel.deb
    sha:dc5fc8fd623166d6799238360e3e86082e2ff7f9
  • cups-ppdc_2.3.3op2-3+deb11u10+tuxcare.els1_armel.deb
    sha:aeb96897323a62a367aca6224e1170a64990f035
  • libcups2_2.3.3op2-3+deb11u10+tuxcare.els1_armel.deb
    sha:8c9057db1dafcd869ba5b5b4ef1deda362c997d5
  • libcups2-dev_2.3.3op2-3+deb11u10+tuxcare.els1_armel.deb
    sha:fb2dd60e12c37a4814fd00d64362c1e8a187f5be
  • libcupsimage2_2.3.3op2-3+deb11u10+tuxcare.els1_armel.deb
    sha:27385a67822af70a30dba523e1b56d054992e60b
  • libcupsimage2-dev_2.3.3op2-3+deb11u10+tuxcare.els1_armel.deb
    sha:697853173b2c5d38c338d9d3f4c70d8ad26d75fc
Notes:
This page is generated automatically and has not been checked for errors. For clarification or corrections please contact the CloudLinux Packaging Team.