{"id":"CVE-2026-87875","summary":"Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound","details":"The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.","aliases":["GHSA-559w-7676-3xrq"],"modified":"2026-09-13T08:02:41.061696Z","published":"2026-09-09T16:06:27.371Z","database_specific":{"cna_assigner":"redhat","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87875.json"},"references":[{"type":"WEB","url":"https://access.redhat.com/downloads/content/package-browser/"},{"type":"WEB","url":"https://catalog.redhat.com/software/containers/"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:66600"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-87875"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87875.json"},{"type":"ADVISORY","url":"https://github.com/OpenPrinting/cups/security/advisories/GHSA-559w-7676-3xrq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87875"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2530994"},{"type":"FIX","url":"https://github.com/OpenPrinting/cups/commit/0c6842fc615e8afa284136a092da8178abf5f142"},{"type":"FIX","url":"https://github.com/OpenPrinting/cups/commit/2b1dc178a2d2325135b855142e384f4e8c42d8e4"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/openprinting/cups","events":[{"introduced":"0"},{"fixed":"0c6842fc615e8afa284136a092da8178abf5f142"},{"fixed":"2b1dc178a2d2325135b855142e384f4e8c42d8e4"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v2.4.19","v2.4.18","v2.4.17","v2.4.16","v2.4.15","v2.4.14","v2.4.13","v2.4.12","v2.4.11","v2.4.10","v2.4.9","v2.4.8","v2.4.7","v2.4.6","v2.4.5","v2.4.3","v2.4.4","v2.4.2","v2.4.1","v2.4.0","v2.4rc1","v2.4b1","v2.3.3op2","v2.3.3op1","v2.3.3","v2.3.1","v2.3.0","v2.3rc1","v2.3b8","v2.3b7","v2.3b6","v2.3b5","v2.3b4","v2.3b3","v2.3b2","v2.3b1","v2.2.6","v2.2.5","v2.2.4","v2.2.3","v2.2.2","v2.2.1","v2.2.0","v2.2rc1","v2.2b2","v2.2b1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87875.json","vanir_signatures_modified":"2026-09-13T08:02:41Z","vanir_signatures":[{"signature_version":"v1","source":"https://github.com/openprinting/cups/commit/2b1dc178a2d2325135b855142e384f4e8c42d8e4","target":{"file":"cups/transcode.h"},"deprecated":false,"digest":{"line_hashes":["282056344467979101780444780055905123273","242845297114462595083827548719364265916","334452425735370591807467877279968958301","310049462854465423984813608395665679181","295662483908832851437989118437492494902","266619866730408558549457950541736672631","140788628626063102588913235564942920376","128791418092717712512335564817177314240","63176061219060814614745211299199857710","15379611401582992488119874624496328000"],"threshold":0.9},"id":"CVE-2026-87875-b56a805c","signature_type":"Line"},{"digest":{"threshold":0.9,"line_hashes":["282056344467979101780444780055905123273","242845297114462595083827548719364265916","334452425735370591807467877279968958301","310049462854465423984813608395665679181","295662483908832851437989118437492494902","266619866730408558549457950541736672631","140788628626063102588913235564942920376","238313407615532658675679934214642124834","267518714214345622598074251992838695072","116120845938343524662087686948682171831"]},"id":"CVE-2026-87875-c47fbccd","signature_type":"Line","signature_version":"v1","source":"https://github.com/openprinting/cups/commit/0c6842fc615e8afa284136a092da8178abf5f142","target":{"file":"cups/transcode.h"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N"}]}