
cupsの脆弱性でCVE-2026-95511が採番された Red hat cve databaseも作成 LPEの緩和策もかいてあるぽい https://access.redhat.com/security/cve/cve-2026-95511
Signal is active with 2 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
NVD description
Rejected reason: Not a vulnerability. Creating a serial queue that overwrites cups-files.conf requires membership in SystemGroups (lpadmin), which is an opt-in cupsd admin role granted by a superuser. No privilege boundary is crossed.
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
NONE
Momentum
NONE

cupsの脆弱性でCVE-2026-95511が採番された Red hat cve databaseも作成 LPEの緩和策もかいてあるぽい https://access.redhat.com/security/cve/cve-2026-95511

🚨HIGH - CUPS cups-filters serial backend arbitrary file write LPE (CVE-2026-95511) In CUPS with cups-filters, an lpadmin user can add a printer using the privileged serial backend and abuse insufficient validation of the path component in non-file device URIs, causing the root-run backend to write attacker-controlled print data to arbitrary files. This enables local priv-esc by overwriting security-sensitive CUPS config and escalating to root code execution when a root-only serial backend binary is present. 👉Affected: cups-filters + cups (serial backend enabled)