ELSA-2026-0312

ELSA-2026-0312 - cups security update

Type:SECURITY
Impact:MODERATE
Release Date:2026-01-08

Description


[1:2.3.3op2-34.2]
- fix use-after-free reported by OSH

[1:2.3.3op2-34.1]
- RHEL-129746 CVE-2025-58436 cups: Slow client communication leads to a possible DoS attack
- RHEL-129738 CVE-2025-61915 cups: Local denial-of-service via cupsd.conf update and related issues


Related CVEs


CVE-2025-58436
CVE-2025-61915

Updated Packages


Release/ArchitectureFilenamesha256Superseded By AdvisoryChannel Label
Oracle Linux 9 (aarch64) cups-2.3.3op2-34.el9_7.2.src.rpmc0511712518dc52f5b765d2b9caa4d654ea23ffbb710c9d2c6d1c63bf9aa3a75-ol9_aarch64_appstream
cups-2.3.3op2-34.el9_7.2.src.rpmc0511712518dc52f5b765d2b9caa4d654ea23ffbb710c9d2c6d1c63bf9aa3a75-ol9_aarch64_baseos_latest
cups-2.3.3op2-34.el9_7.2.src.rpmc0511712518dc52f5b765d2b9caa4d654ea23ffbb710c9d2c6d1c63bf9aa3a75-ol9_aarch64_u7_baseos_patch
cups-2.3.3op2-34.el9_7.2.aarch64.rpm29d163d287c0b19c0c323da6c44b61b0e81342937d64ce71be74a86e4460ffc1-ol9_aarch64_appstream
cups-client-2.3.3op2-34.el9_7.2.aarch64.rpm1551d18b224a327ea6ae2d2232803b149133a67f67297e03cf6d8e476c8c3db3-ol9_aarch64_appstream
cups-devel-2.3.3op2-34.el9_7.2.aarch64.rpm5ddcbe170841cfd2f2bcfbd23a0f54bb4c7f52e7eeb8cf7489041dcc7963e977-ol9_aarch64_appstream
cups-filesystem-2.3.3op2-34.el9_7.2.noarch.rpm0f07974c20f2d691c138ef3382efca97fd609528c782349d37f05b3a3a6a0e78-ol9_aarch64_appstream
cups-ipptool-2.3.3op2-34.el9_7.2.aarch64.rpm0da7373e6a107cf5a220f709a7e9c634204130f1259a4252d098e910c8b112af-ol9_aarch64_appstream
cups-libs-2.3.3op2-34.el9_7.2.aarch64.rpm38b8f770c5f84fb046bf2d9f8b61e684befcf88519305e2ce3feeea689ddb29e-ol9_aarch64_baseos_latest
cups-libs-2.3.3op2-34.el9_7.2.aarch64.rpm38b8f770c5f84fb046bf2d9f8b61e684befcf88519305e2ce3feeea689ddb29e-ol9_aarch64_u7_baseos_patch
cups-lpd-2.3.3op2-34.el9_7.2.aarch64.rpm73b8ec03c0d06653e0a2470b770aeb03ea70ea63f3be87093bf7af4e9a82b32f-ol9_aarch64_appstream
cups-printerapp-2.3.3op2-34.el9_7.2.aarch64.rpmc67084334feebb750d5194bda98b0fada5fc8d081ece17e767e94f54e35948ce-ol9_aarch64_appstream
Oracle Linux 9 (x86_64) cups-2.3.3op2-34.el9_7.2.src.rpmc0511712518dc52f5b765d2b9caa4d654ea23ffbb710c9d2c6d1c63bf9aa3a75-ol9_x86_64_appstream
cups-2.3.3op2-34.el9_7.2.src.rpmc0511712518dc52f5b765d2b9caa4d654ea23ffbb710c9d2c6d1c63bf9aa3a75-ol9_x86_64_baseos_latest
cups-2.3.3op2-34.el9_7.2.src.rpmc0511712518dc52f5b765d2b9caa4d654ea23ffbb710c9d2c6d1c63bf9aa3a75-ol9_x86_64_u7_baseos_patch
cups-2.3.3op2-34.el9_7.2.x86_64.rpm82909f207ee0018358f7dec66e1985b5a250061d69645d22a58182280025faa1-ol9_x86_64_appstream
cups-client-2.3.3op2-34.el9_7.2.x86_64.rpm78fe2858e3c135779b09974ac1b1aba79195e458b824fd448e71350af1dd03df-ol9_x86_64_appstream
cups-devel-2.3.3op2-34.el9_7.2.i686.rpm5ebdad601aa20d89ab80f4b6de3683f2069d335cba2527996771c549517498f4-ol9_x86_64_appstream
cups-devel-2.3.3op2-34.el9_7.2.x86_64.rpm145faf7c3bc40b75bfab0e5cccd63a767b965c6025d1aaf83206d476349f6263-ol9_x86_64_appstream
cups-filesystem-2.3.3op2-34.el9_7.2.noarch.rpm0f07974c20f2d691c138ef3382efca97fd609528c782349d37f05b3a3a6a0e78-ol9_x86_64_appstream
cups-ipptool-2.3.3op2-34.el9_7.2.x86_64.rpm4e87a869a01b11c55d1929e62879657cf8c1396298aa339609ec2dc5b03791f8-ol9_x86_64_appstream
cups-libs-2.3.3op2-34.el9_7.2.i686.rpm202bc04897a7ad765683d9b7ee428ea9c8ce8c97e614321869b6fc9062fa6c80-ol9_x86_64_baseos_latest
cups-libs-2.3.3op2-34.el9_7.2.i686.rpm202bc04897a7ad765683d9b7ee428ea9c8ce8c97e614321869b6fc9062fa6c80-ol9_x86_64_u7_baseos_patch
cups-libs-2.3.3op2-34.el9_7.2.x86_64.rpmdb538aeeab8941bc8efb9ad74abd9ba835d6ddc037e6d89d9054c16fca4794a0-ol9_x86_64_baseos_latest
cups-libs-2.3.3op2-34.el9_7.2.x86_64.rpmdb538aeeab8941bc8efb9ad74abd9ba835d6ddc037e6d89d9054c16fca4794a0-ol9_x86_64_u7_baseos_patch
cups-lpd-2.3.3op2-34.el9_7.2.x86_64.rpm913ce12ca3a2d6efd3ef65dcd849281f5efc5c73f1022610014b7b1f2c2f23e4-ol9_x86_64_appstream
cups-printerapp-2.3.3op2-34.el9_7.2.x86_64.rpm64f9da0120bb6e906e05bbcfacd3e7106b19197560549a3af6f9eebf8b5d8341-ol9_x86_64_appstream



This page is generated automatically and has not been checked for errors or omissions. For clarification or corrections please contact the Oracle Linux ULN team

software.hardware.complete