New vulnerabilities affect printing software on Linux and Unix

TL;DR AI
2 min readKey summary
Security researchers found two vulnerabilities in CUPS 2.4.16 that can be combined for remote code execution without credentials.
One flaw allows unauthenticated print jobs on shared queues; the other lets a local user force connections to malicious print services to overwrite files as root.
Patches are available but no official CUPS update has been released yet, and public exploit samples plus AI tools make attacks easier to implement.
Organizations should review printer queue configurations and restrict access until an official update is installed.



