{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/tags/printer-vulnerability/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-64611"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["libcupsfilters","cups-filters","Red Hat Enterprise Linux 10","Red Hat Enterprise Linux 7","Red Hat Enterprise Linux 8","Red Hat Enterprise Linux 9"],"_cs_severities":["low"],"_cs_tags":["vulnerability","denial-of-service","linux","printer-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Red Hat","OpenPrinting"],"content_html":"\u003cp\u003eA significant denial of service vulnerability, identified as CVE-2026-64611, has been discovered in the \u003ccode\u003elibcupsfilters\u003c/code\u003e library, specifically within the \u003ccode\u003ecfIEEE1284NormalizeMakeModel()\u003c/code\u003e function. This flaw allows a network-adjacent attacker to trigger an infinite loop by transmitting a specially crafted printer advertisement. The vulnerability is activated when the \u003ccode\u003elibcupsfilters\u003c/code\u003e component processes an IEEE-1284 device ID that includes an empty model field. This processing error leads to sustained CPU consumption on the affected system, effectively rendering the printing services or the entire system unresponsive. The bug is critical for environments where \u003ccode\u003elibcupsfilters\u003c/code\u003e is used, particularly Red Hat Enterprise Linux systems. This vulnerability highlights the importance of input validation in network-facing services and the potential for seemingly innocuous data fields to be exploited for resource exhaustion.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eA network-adjacent attacker gains access to the same local network segment as the vulnerable system running \u003ccode\u003elibcupsfilters\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe attacker broadcasts a specially crafted printer advertisement packet on the network.\u003c/li\u003e\n\u003cli\u003eThis advertisement includes an IEEE-1284 device ID containing an empty model field, deviating from expected specifications.\u003c/li\u003e\n\u003cli\u003eThe vulnerable system, using \u003ccode\u003elibcupsfilters\u003c/code\u003e, receives and attempts to process this malformed printer advertisement.\u003c/li\u003e\n\u003cli\u003eSpecifically, the \u003ccode\u003ecfIEEE1284NormalizeMakeModel()\u003c/code\u003e function within \u003ccode\u003elibcupsfilters\u003c/code\u003e is invoked to handle the IEEE-1284 device ID.\u003c/li\u003e\n\u003cli\u003eDue to the empty model field, the \u003ccode\u003ecfIEEE1284NormalizeMakeModel()\u003c/code\u003e function enters an infinite loop, consuming all available CPU resources.\u003c/li\u003e\n\u003cli\u003eThe sustained CPU consumption leads to a denial of service condition, making the system or its printing services unresponsive.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-64611 results in a complete denial of service for systems running \u003ccode\u003elibcupsfilters\u003c/code\u003e, such as Red Hat Enterprise Linux 7, 8, 9, and 10. The infinite loop triggered by a malformed printer advertisement causes sustained and maximum CPU utilization, preventing legitimate users or services from accessing system resources. This could lead to significant operational disruptions, loss of data processing capabilities for printing-related tasks, and potential service outages in affected organizations. While no specific victim counts are provided, any organization utilizing the vulnerable \u003ccode\u003elibcupsfilters\u003c/code\u003e versions within a network where an attacker can send printer advertisements is at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch CVE-2026-64611 immediately on all affected Red Hat Enterprise Linux systems to mitigate the denial of service vulnerability.\u003c/li\u003e\n\u003cli\u003eMonitor network traffic for unusual or malformed printer advertisement broadcasts, though specific signatures may be difficult to define without further details on the crafted packets.\u003c/li\u003e\n\u003cli\u003eReview network segmentation to limit the reach of network-adjacent attackers to critical systems that utilize \u003ccode\u003elibcupsfilters\u003c/code\u003e.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-23T11:18:52Z","date_published":"2026-07-23T11:18:52Z","id":"https://feed.craftedsignal.io/briefs/2026-07-libcupsfilters-dos/","summary":"A high-severity denial of service vulnerability, CVE-2026-64611, exists in the `cfIEEE1284NormalizeMakeModel()` function of libcupsfilters, allowing a network-adjacent attacker to cause sustained CPU consumption and system unresponsiveness by broadcasting a specially crafted printer advertisement with an empty model field in the IEEE-1284 device ID.","title":"CVE-2026-64611: libcupsfilters Denial of Service via Malformed Printer Advertisement","url":"https://feed.craftedsignal.io/briefs/2026-07-libcupsfilters-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Printer-Vulnerability","version":"https://jsonfeed.org/version/1.1"}