{"id":"CVE-2025-61915","summary":"OpenPrinting CUPS vulnerable to stack based out-of-bound write","details":"OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. Prior to version 2.4.15, a user in the lpadmin group can use the cups web ui to change the config and insert a malicious line. Then the cupsd process which runs as root will parse the new config and cause an out-of-bound write. This issue has been patched in version 2.4.15.","aliases":["GHSA-hxm8-vfpq-jrfc"],"modified":"2026-08-12T15:14:20.874221Z","published":"2025-11-29T02:15:39.913Z","related":["ALSA-2026:0312","ALSA-2026:0464","ALSA-2026:0596","SUSE-SU-2025:4289-1","SUSE-SU-2025:4290-1","SUSE-SU-2026:20229-1","SUSE-SU-2026:20231-1","SUSE-SU-2026:20528-1","SUSE-SU-2026:20535-1","openSUSE-SU-2026:10088-1","openSUSE-SU-2026:20172-1"],"database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-124","CWE-129"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/61xxx/CVE-2025-61915.json"},"references":[{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2025/11/27/5"},{"type":"WEB","url":"https://github.com/OpenPrinting/cups/releases/tag/v2.4.15"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/61xxx/CVE-2025-61915.json"},{"type":"ADVISORY","url":"https://github.com/OpenPrinting/cups/security/advisories/GHSA-hxm8-vfpq-jrfc"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-61915"},{"type":"FIX","url":"https://github.com/OpenPrinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openprinting/cups","events":[{"introduced":"0"},{"fixed":"433af45db06759081d4f3cd606e08ca634fc490a"},{"fixed":"db8d560262c22a21ee1e55dfd62fa98d9359bcb0"}],"database_specific":{"cpe":"cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.4.15"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.4.14","v2.4.13","v2.4.12","v2.4.11","v2.4.10","v2.4.9","v2.4.8","v2.4.7","v2.4.6","v2.4.5","v2.4.3","v2.4.4","v2.4.2","v2.4.1","v2.4.0","v2.4rc1","v2.4b1","v2.3.3op2","v2.3.3op1","v2.3.3","v2.3.1","v2.3.0","v2.3rc1","v2.3b8","v2.3b7","v2.3b6","v2.3b5","v2.3b4","v2.3b3","v2.3b2","v2.3b1","v2.2.6","v2.2.5","v2.2.4","v2.2.3","v2.2.2","v2.2.1","v2.2.0","v2.2rc1","v2.2b2","v2.2b1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-61915.json","vanir_signatures_modified":"2026-08-12T15:14:20Z","vanir_signatures":[{"deprecated":false,"digest":{"function_hash":"216088593647566359765054349652386305695","length":2656},"id":"CVE-2025-61915-3f9816b7","signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","target":{"file":"scheduler/client.c","function":"cupsdSendHeader"}},{"signature_version":"v1","source":"https://github.com/openprinting/cups/commit/433af45db06759081d4f3cd606e08ca634fc490a","target":{"file":"cups/cups.h"},"deprecated":false,"digest":{"line_hashes":["77478087155392166827753678322261110249","199629161088706978755561407205027215243","242761163277272059188145473982024142479","31183038617601839798647281261141047645","290956483188464259330199195401068909924","47716117503936234012778123479968869248","127641381619247502457438674603461877569"],"threshold":0.9},"id":"CVE-2025-61915-43860eb9","signature_type":"Line"},{"digest":{"function_hash":"116534588722075144612802403024145414356","length":26771},"id":"CVE-2025-61915-4a8dc041","signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","target":{"file":"scheduler/conf.c","function":"cupsdReadConfiguration"},"deprecated":false},{"source":"https://github.com/openprinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","target":{"function":"get_addr_and_mask","file":"scheduler/conf.c"},"deprecated":false,"digest":{"function_hash":"104261167883171139398146729166003032209","length":3894},"id":"CVE-2025-61915-4acf061d","signature_type":"Function","signature_version":"v1"},{"signature_version":"v1","source":"https://github.com/openprinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","target":{"file":"scheduler/conf.c","function":"read_cups_files_conf"},"deprecated":false,"digest":{"function_hash":"67375267238121054000862264853345401157","length":5834},"id":"CVE-2025-61915-4d3116cb","signature_type":"Function"},{"deprecated":false,"digest":{"function_hash":"13842703268685403691677718554416182261","length":11306},"id":"CVE-2025-61915-86919846","signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","target":{"file":"scheduler/conf.c","function":"read_cupsd_conf"}},{"deprecated":false,"digest":{"line_hashes":["255539927429473817935248946750780519443","272480313272899782896572657404550074990","45492756319726350602163543023748310477","239117421071019999106137472253588797541","10734597077417368791326228453666278027","116858488929775327606895029848323007686","101977648965470410612112220981350678599"],"threshold":0.9},"id":"CVE-2025-61915-ac14f1b0","signature_type":"Line","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","target":{"file":"scheduler/auth.c"}},{"signature_version":"v1","source":"https://github.com/openprinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","target":{"file":"scheduler/client.c"},"deprecated":false,"digest":{"line_hashes":["120607244496947570681525043187521150832","88659061422635154964646960060321878117","5054793461934368021432167206148145114","44899294183624763843399388768618330648"],"threshold":0.9},"id":"CVE-2025-61915-b667dd7d","signature_type":"Line"},{"source":"https://github.com/openprinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","target":{"file":"scheduler/auth.h"},"deprecated":false,"digest":{"line_hashes":["131948804428591578494982273550036425213","86005996497549144972705986824223955847","294904371515449405612770812609323019322","11961284096522407210249507208104171350"],"threshold":0.9},"id":"CVE-2025-61915-bce5f172","signature_type":"Line","signature_version":"v1"},{"source":"https://github.com/openprinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","target":{"file":"scheduler/conf.c"},"deprecated":false,"digest":{"line_hashes":["174434162343234898327860864647089309796","56679419231619399088007085586932060595","40248741802651320805583868069510182065","6933372024758400797764704871463293298","292335270112130092247030320426031090613","162449232877538213156371640502487016088","234599886714764638290226966416384742280","204393689061886564847851372537513092511","231732167570505312881391839488141926684","41545548436468301163684113602346350161","264585810411964675367361184006441788956","25252038449115446462232986285924861913","215011195236978653665689866561290221709","315931924591229393007590713237359678040","43944374017982855509262875743499359705","68338111734799727756276547800512832430","46829838376641345876370869851988968559","322175433090889536558190607010766802131","295605020560383952032960061693817810975","73014115699374684679699640103429868881","327176999695018481761342635709439162525","331975924165036499360621484165509171055","250968327213018094340603780731921162048","93527768243908812257032525787595450810","132524112903181301240262205763983444083","265215214344898382029704942942221011746","17127792572793164733301321789670536163","228346616067449597029532324471779097958","156266458837255803360607174964751672119","182746429635265099113388143294225438366","195748296568088409920858519418955435699","80918916449579318845810020320742448770","15341225919275437538568875297038479187","1658150463273145651170069368127982350","168431899460148161318941288419143459703","246421001059074081096123531234919823670","8405263872762192675017997417936794611","334697382658674961754492331917768147980","166780202739238526151708887915131838623","198234769637519306419840839811329122554","173159145193159605049618083986359893260"],"threshold":0.9},"id":"CVE-2025-61915-d47892d8","signature_type":"Line","signature_version":"v1"},{"source":"https://github.com/openprinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","target":{"file":"scheduler/conf.c","function":"parse_variable"},"deprecated":false,"digest":{"function_hash":"149086396008766977698399470819942787457","length":5205},"id":"CVE-2025-61915-f30e875b","signature_type":"Function","signature_version":"v1"},{"deprecated":false,"digest":{"function_hash":"76681408033357677209677801970894634677","length":11736},"id":"CVE-2025-61915-ffbc5b16","signature_type":"Function","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/db8d560262c22a21ee1e55dfd62fa98d9359bcb0","target":{"function":"cupsdAuthorize","file":"scheduler/auth.c"}}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:N/I:N/A:H"}]}