CVE-2026-34979: OpenPrinting CUPS: Heap overflow in `get_options()`
Last updated 8 June 2026
Other sources
OpenPrinting CUPS is an open source printing system for Linux and other Unix-like operating systems. In versions 2.4.16 and prior, there is a heap-based buffer overflow in the CUPS scheduler when building filter option strings from job attribute. At time of publication, there are no publicly available patches.
— MITRE
OpenPrinting CUPS: Heap overflow in getoptions()
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/cupsto a version that resolves this vulnerability.Fixed in 2.4.18-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-34979?
CVE-2026-34979 is classified as a high-severity vulnerability due to the potential for remote code execution through a heap overflow.
How do I fix CVE-2026-34979?
To fix CVE-2026-34979, upgrade OpenPrinting CUPS to version 2.4.17 or later where the vulnerability has been patched.
What types of systems are affected by CVE-2026-34979?
CVE-2026-34979 affects Linux and other Unix-like operating systems running OpenPrinting CUPS versions up to and including 2.4.16.
What is the nature of the vulnerability in CVE-2026-34979?
CVE-2026-34979 involves a heap-based buffer overflow in the CUPS scheduler during the processing of filter option strings from job attributes.
Can CVE-2026-34979 be exploited remotely?
Yes, CVE-2026-34979 can potentially be exploited remotely by sending specially crafted print jobs to an affected CUPS server.