{"id":"AZL-83627","summary":"CVE-2026-41079 affecting package cups for versions less than 2.4.18-1","details":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to 2.4.17, a network-adjacent attacker can send a crafted SNMP response to the CUPS SNMP backend that causes an out-of-bounds read of up to 176 bytes past a stack buffer. The leaked memory is converted from UTF-16 to UTF-8 and stored as printer supply description strings, which are subsequently visible to authenticated users via IPP Get-Printer-Attributes responses and the CUPS web interface. This vulnerability is fixed in 2.4.17.","modified":"2026-08-28T17:47:57.061780142Z","published":"2026-04-24T17:16:21Z","upstream":["CVE-2026-41079"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41079"}],"affected":[{"package":{"name":"cups","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/cups"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.4.18-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-83627.json"}}],"schema_version":"1.9.0"}