Two critical vulnerabilities have been discovered in Linux CUPS (Common Unix Printing System), exposing millions of systems to remote denial-of-service (DoS) attacks and authentication bypass exploits.
See also: 'Sindoor Dropper': New malware campaign targets Linux

The vulnerabilities, codenamed CVE-2025-58364 and CVE-2025-58060, affect the core printing infrastructure used in almost all Linux distributions and pose significant risks to network security.
The first vulnerability, CVE-2025-58364, stems from unsafe printer attribute deselecting and validation in the libcups. This moderate severity vulnerability allows attackers to cause a null reference via crafted printer attribute responses, causing system crashes on local networks.
The vulnerability manifests itself in the ipp_read_io() when processing IPP_OP_GET_PRINTER_ATTRIBUTES. Security researchers have shown that the combination of the ippNewRequest(), cupsDoRequest() , and ippValidateAttributes() creates a dangerous code path where malicious responses can cause null references.
The attack vector requires access to a neighboring network, making it exploitable within local subnets where Linux CUPS services automatically discover printers. Systems running the cups-browsed service are particularly vulnerable, as the service actively listens for printer announcements on the network. The vulnerability affects all Linux CUPS versions below 2.4.12, with no patches available. The vulnerability was discovered and reported by security researcher SilverPlate3.
See also: Hackers exploit Windows and Linux vulnerabilities

CVE-2025-58060 represents a high severity authentication bypass vulnerability affecting Linux CUPS configurations that use AuthType Negotiate or any non-Basic authentication method. The vulnerability allows attackers to bypass password verification by sending Authorization: Basic headers when the system expects different authentication types.
The vulnerability exists in the scheduler/auth.c file in the cupsdAuthorize() function . When administrators configure DefaultAuthType to anything other than Basic Authentication, the system incorrectly skips password verification if an incoming request contains a Basic Authentication header. Attackers can exploit this by sending requests with Authorization: Basic $(echo -n admin:x | base64), where the password can be any arbitrary string. This bypass provides unauthorized access to Linux CUPS administrative functions, potentially allowing attackers to modify printer configurations, access print queues, or execute administrative commands.
The vulnerability affects systems where administrators have implemented Kerberos, LDAP , or other enterprise authentication mechanisms to secure their printing infrastructure. The vulnerability was discovered and reported by researcher hvenev-insait.
Both vulnerabilities expose critical weaknesses in CUPS installations on business and home networks. The DoS vulnerability could disrupt network-wide printing services, while the authentication bypass undermines administrative access controls.
See also: Hackers deploy Linux Auto-Color via SAP NetWeaver flaw

Organizations using Linux CUPS in production environments should immediately assess their exposure and implement network-level protections. Network administrators should restrict access to IPP port 631 through firewalls and disable the cups-browsed service on systems that do not require automatic printer discovery. For the authentication bypass vulnerability, temporarily reverting to AuthType Basic with strong passwords provides immediate protection until patches are available. Organizations should monitor the OpenPrinting for security updates and apply patches as soon as they are released.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
