CVE-2026-39314: CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported`
Published Apr 7, 2026
·Updated
CUPS has an integer underflow in `_ppdCreateFromIPP` causes root cupsd crash via negative `job-password-supported`
Affected Software
3 affected componentsFixes available
Event History
Apr 7, 2026
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Apr 9, 2026
Data Sourced
via Microsoft·08:01 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·08:01 AM
Affected Software
Updated
via Microsoft·08:01 AM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2026-39314?
CVE-2026-39314 is considered a critical vulnerability due to its potential to crash the root cupsd service.
2
How do I fix CVE-2026-39314?
To fix CVE-2026-39314, users should update OpenPrinting CUPS to version 2.4.17 or later.
3
What versions of CUPS are affected by CVE-2026-39314?
CVE-2026-39314 affects OpenPrinting CUPS versions 2.4.16 and prior.
4
What kind of vulnerability is CVE-2026-39314?
CVE-2026-39314 is an integer underflow vulnerability in the `_ppdCreateFromIPP` function.
5
What can happen if CVE-2026-39314 is exploited?
If exploited, CVE-2026-39314 can lead to a root cupsd crash, potentially causing disruption in the printing service.