- Description
- OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and validation of printer attributes causes null dereference in the libcups library. This is a remote DoS vulnerability available in local subnet in default configurations. It can cause the cups & cups-browsed to crash, on all the machines in local network who are listening for printers (so by default for all regular linux machines). On systems where the vulnerability CVE-2024-47176 (cups-filters 1.x/cups-browsed 2.x vulnerability) was not fixed, and the firewall on the machine does not reject incoming communication to IPP port, and the machine is set to be available to public internet, attack vector "Network" is possible. The current versions of CUPS and cups-browsed projects have the attack vector "Adjacent" in their default configurations. Version 2.4.13 contains a patch for CVE-2025-58364.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- cups
CVSS 3.1
- Type
- Secondary
- Base score
- 6.5
- Impact score
- 3.6
- Exploitability score
- 2.8
- Vector string
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Severity
- MEDIUM
- security-advisories@github.com
- CWE-20
- Hype score
- Not currently trending
CVE-2025-58060: CUPS: Authentication bypass with AuthType Negotiate https://t.co/mAvLgwKphE CVE-2025-58364: CUPS: Remote DoS via null dereference https://t.co/VOuFIts4Iy
@oss_security
17 Sept 2025
132 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
🚨 Vulnerabilidad de CUPS en Linux permite a atacantes realizar ataques DoS remotos y eludir la autenticación ➡️ Linux Common Unix Printing System (CUPS) ⚠️ CVE-2025-58364 ⚠️ CVE-2025-58060 https://t.co/jHsB1LZ1Sf https://t.co/g0KsAen9FI
@elhackernet
16 Sept 2025
2294 Impressions
10 Retweets
28 Likes
3 Bookmarks
0 Replies
0 Quotes
⚠️ Linux CUPS Alert! Two new flaws (CVE-2025-58364 & CVE-2025-58060) let attackers crash printing services 🖨️ & bypass admin authentication 🔑. Block port 631 + disable auto-discovery until patches drop! 🔗 https://t.co/LKZM6ZLCXq #Linux #CUPS #CyberSecurity
@VaultEdgeIT
15 Sept 2025
48 Impressions
0 Retweets
1 Like
0 Bookmarks
0 Replies
0 Quotes
📢 𝐍𝐞𝐰 𝐂𝐕𝐄 𝐚𝐧𝐚𝐥𝐲𝐬𝐢𝐬 𝐣𝐮𝐬𝐭 𝐝𝐫𝐨𝐩𝐩𝐞𝐝! CUPS on Linux is vulnerable to critical exploits-learn how CVE-2025-58060 and CVE-2025-58364 can crash services or bypass authentication entirely. 👉 Dive into the fu
@PurpleOps_io
15 Sept 2025
9 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CUPSに2つの重大な脆弱性(CVE-2025-58364とCVE-2025-58060)が発見され、Linuxシステムがリモート攻撃にさらされています。CVE-2025-58364はサービス妨害を引き起こし、CVE-2025-58060は認証バイパスを可能にします。両者と
@cyber_edu_jp
15 Sept 2025
61 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🗣️ CUPS Flaws Allow Linux Remote DoS (CVE-2025-58364) and Authentication Bypass (CVE-2025-58060) https://t.co/ykg6KfY7L3
@fridaysecurity
15 Sept 2025
70 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
URGENT: #SUSE patches critical CUPS flaws in SLES 12 SP5. CVE-2025-58060 (Auth Bypass, CVSS 8.0) CVE-2025-58364 (DoS, CVSS 6.5) Patch immediately to protect print servers from remote exploitation. Read more:👉 https://t.co/flcFivXlgV #Security https://t.co/2EfViVmn97
@Cezar_H_Linux
13 Sept 2025
79 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2025-58364 OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.12 and earlier, an unsafe deserialization and val… https://t.co/VA6ieZzqTK
@CVEnew
11 Sept 2025
491 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*",
"matchCriteriaId": "9352DF89-76A8-4760-9846-45BC66C471AE",
"versionEndExcluding": "2.4.13",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]