CVE-2026-87875 - Cups: openprinting cups: heap out-of-bounds read in cupsutf32toutf8() via missing source-length bound
CVE ID :CVE-2026-87875
Published : Sept. 9, 2026, 5:17 p.m. | 1 hour, 48 minutes ago
Description :The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 9, 2026, 5:17 p.m. | 1 hour, 48 minutes ago
Description :The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
Severity: 4.3 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...