|
|
Message-ID: <f30121aa-5fa6-4d1c-93f2-2c1e3032a6a2@redhat.com> Date: Thu, 27 Nov 2025 16:10:53 +0100 From: Zdenek Dohnal <zdohnal@...hat.com> To: oss-security@...ts.openwall.com Subject: CVE-2025-58436 cups: Slow client communication leads to a possible DoS attack Hi all, we have CVE-2025-58436 reported by pzirnik, jsmeix, cmatos689, msmeissn - it is moderate CVE with CVSS score CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H The published advisory: https://github.com/OpenPrinting/cups/security/advisories/GHSA-8wpw-vfgm-qrrr The commits fixing the issue: - master: https://github.com/OpenPrinting/cups/commit/40008d76a001babbb9beb9d9d74b01a86fb6ddb4 - 2.4.x: https://github.com/OpenPrinting/cups/commit/5d414f1f91bdca118413301b148f0b188eb1cdc6 Have a nice day! Zdenek -- Zdenek Dohnal Senior Software Engineer Red Hat, BRQ-TPBC
Powered by blists - more mailing lists
Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.
Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.