Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Message-ID: <f30121aa-5fa6-4d1c-93f2-2c1e3032a6a2@redhat.com>
Date: Thu, 27 Nov 2025 16:10:53 +0100
From: Zdenek Dohnal <zdohnal@...hat.com>
To: oss-security@...ts.openwall.com
Subject: CVE-2025-58436 cups: Slow client communication leads to a possible
 DoS attack

Hi all,

we have CVE-2025-58436 reported by pzirnik, jsmeix, cmatos689, msmeissn 
- it is moderate CVE with CVSS 
score CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

The published advisory: 
https://github.com/OpenPrinting/cups/security/advisories/GHSA-8wpw-vfgm-qrrr

The commits fixing the issue:

- master: 
https://github.com/OpenPrinting/cups/commit/40008d76a001babbb9beb9d9d74b01a86fb6ddb4

- 2.4.x: 
https://github.com/OpenPrinting/cups/commit/5d414f1f91bdca118413301b148f0b188eb1cdc6


Have a nice day!

Zdenek

-- 
Zdenek Dohnal
Senior Software Engineer
Red Hat, BRQ-TPBC

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.