CVE-2025-58364

Published Sep 11, 2025

Last updated a year ago

Overview

Description
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation of printer attributes causes null dereference in the libcups library. This is a remote DoS vulnerability available in local subnet in default configurations. It can cause the cups & cups-browsed to crash, on all the machines in local network who are listening for printers (so by default for all regular linux machines). On systems where the vulnerability CVE-2024-47176 (cups-filters 1.x/cups-browsed 2.x vulnerability) was not fixed, and the firewall on the machine does not reject incoming communication to IPP port, and the machine is set to be available to public internet, attack vector "Network" is possible. The current versions of CUPS and cups-browsed projects have the attack vector "Adjacent" in their default configurations. Version 2.4.13 contains a patch for CVE-2025-58364.
Source
security-advisories@github.com
NVD status
Analyzed
Products
cups

Risk scores

CVSS 3.1

Type
Secondary
Base score
6.5
Impact score
3.6
Exploitability score
2.8
Vector string
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity
MEDIUM

Weaknesses

security-advisories@github.com
CWE-20

Social media

Hype score
Not currently trending
  1. CVE-2025-58060: CUPS: Authentication bypass with AuthType Negotiate https://t.co/mAvLgwKphE CVE-2025-58364: CUPS: Remote DoS via null dereference https://t.co/VOuFIts4Iy

    @oss_security

    17 Sept 2025

    132 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  2. 🚨 Vulnerabilidad de CUPS en Linux permite a atacantes realizar ataques DoS remotos y eludir la autenticación ➡️ Linux Common Unix Printing System (CUPS) ⚠️ CVE-2025-58364 ⚠️ CVE-2025-58060 https://t.co/jHsB1LZ1Sf https://t.co/g0KsAen9FI

    @elhackernet

    16 Sept 2025

    2294 Impressions

    10 Retweets

    28 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  3. ⚠️ Linux CUPS Alert! Two new flaws (CVE-2025-58364 & CVE-2025-58060) let attackers crash printing services 🖨️ & bypass admin authentication 🔑. Block port 631 + disable auto-discovery until patches drop! 🔗 https://t.co/LKZM6ZLCXq #Linux #CUPS #CyberSecurity

    @VaultEdgeIT

    15 Sept 2025

    48 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 📢 𝐍𝐞𝐰 𝐂𝐕𝐄 𝐚𝐧𝐚𝐥𝐲𝐬𝐢𝐬 𝐣𝐮𝐬𝐭 𝐝𝐫𝐨𝐩𝐩𝐞𝐝! CUPS on Linux is vulnerable to critical exploits-learn how CVE-2025-58060 and CVE-2025-58364 can crash services or bypass authentication entirely. 👉 Dive into the fu

    @PurpleOps_io

    15 Sept 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. CUPSに2つの重大な脆弱性(CVE-2025-58364とCVE-2025-58060)が発見され、Linuxシステムがリモート攻撃にさらされています。CVE-2025-58364はサービス妨害を引き起こし、CVE-2025-58060は認証バイパスを可能にします。両者と

    @cyber_edu_jp

    15 Sept 2025

    61 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🗣️ CUPS Flaws Allow Linux Remote DoS (CVE-2025-58364) and Authentication Bypass (CVE-2025-58060) https://t.co/ykg6KfY7L3

    @fridaysecurity

    15 Sept 2025

    70 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. URGENT: #SUSE patches critical CUPS flaws in SLES 12 SP5. CVE-2025-58060 (Auth Bypass, CVSS 8.0) CVE-2025-58364 (DoS, CVSS 6.5) Patch immediately to protect print servers from remote exploitation. Read more:👉 https://t.co/flcFivXlgV #Security https://t.co/2EfViVmn97

    @Cezar_H_Linux

    13 Sept 2025

    79 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. CVE-2025-58364 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and val… https://t.co/VA6ieZzqTK

    @CVEnew

    11 Sept 2025

    491 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations