<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:openprinting:cups-Browsed:2.0.1:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aopenprintingcups-browsed2.0.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 12 Aug 2026 16:45:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aopenprintingcups-browsed2.0.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Remote Code Execution Vulnerability in CUPS</title><link>https://feed.craftedsignal.io/briefs/2026-08-cups-rce/</link><pubDate>Wed, 12 Aug 2026 16:45:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-cups-rce/</guid><description>A vulnerability in the cups-browsed service allows a local attacker to achieve arbitrary code execution via malicious print queue discovery packets.</description><content:encoded><![CDATA[<p>The Common Unix Printing System (CUPS) is affected by a security flaw, identified as CVE-2024-47176, which resides in the cups-browsed service. This service is responsible for discovering printers on a network. The vulnerability arises from improper handling of packet data received during the printer discovery process. A local attacker can craft malicious discovery packets that, when processed by cups-browsed, lead to the execution of arbitrary commands on the host system. Given that cups-browsed often runs with elevated privileges, this flaw poses a significant risk for privilege escalation and system compromise on affected Linux systems. Defenders should prioritize patching the CUPS stack and reviewing the necessity of the cups-browsed service in their environment.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a local attacker to execute arbitrary code with the privileges of the cups-browsed service. This can lead to full system compromise, unauthorized data access, and persistence on the affected machine. This vulnerability affects Linux systems where CUPS and the associated cups-browsed service are deployed, potentially impacting enterprise workstations, servers, and embedded devices that utilize standard Linux printing configurations.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the CUPS package to the latest version provided by your Linux distribution maintainer to address CVE-2024-47176.</li>
<li>Disable the cups-browsed service if network printer discovery is not required for the system function.</li>
<li>Review network configurations to restrict access to CUPS discovery ports if the service must remain enabled.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>rce</category><category>linux</category></item></channel></rss>