{"id":"AZL-100920","summary":"CVE-2026-87875 affecting package cups 2.4.19-1","details":"The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.","modified":"2026-09-14T17:34:05Z","published":"2026-09-09T17:17:53Z","upstream":["CVE-2026-87875"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87875"}],"affected":[{"package":{"name":"cups","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/cups"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.4.19-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-100920.json"}}],"schema_version":"1.9.0"}