Vulnerability record · CVE-2024-47076 · published 26 September 2024
CVE-2024-47076: libcupsfilters missing IPP attribute sanitization in cfGetPrinterAttributes5
Openprinting · Libcupsfilters
The cfGetPrinterAttributes5 function in libcupsfilters does not sanitize IPP attributes returned by an IPP server. When those attributes are consumed, for example to generate a PPD file, attacker-controlled data flows into the rest of the CUPS system. This is one component of the CUPS remote code execution chain disclosed in 2024, so it matters to any host running CUPS with cups-browsed or related browsing components.
Description
CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Automated analysis
high priorityCVSS 8.6 with network reachability, no authentication or interaction, and very high EPSS plus public exploit references, though it is not in KEV and is one link in a chain rather than a standalone RCE.
What it is
The cfGetPrinterAttributes5 function in libcupsfilters does not sanitize IPP attributes returned by an IPP server. When those attributes are consumed, for example to generate a PPD file, attacker-controlled data flows into the rest of the CUPS system. This is one component of the CUPS remote code execution chain disclosed in 2024, so it matters to any host running CUPS with cups-browsed or related browsing components.
Impact
An attacker can inject arbitrary data into CUPS processing, which in the disclosed chain is used to achieve remote code execution on the affected host. On its own, the flaw gives an attacker control over data consumed by downstream CUPS components.
Attack surface
Reachable over the network with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The attacker needs to be able to act as or spoof an IPP server that the CUPS client or browsing daemon contacts.
Exploitation
Not listed in CISA KEV, but EPSS is 0.77644 (99.54th percentile) and multiple references are tagged Exploit, including the vendor advisory and a third-party writeup. Public exploitation activity is therefore likely.
What to do
- Apply the libcupsfilters patch (commit 95576ec3d20c109332d14672a807353cdc551018) and the coordinated cups-browsed, cups-filters and libppd fixes.
- Update to the fixed packages from your distribution (Debian LTS advisory and vendor advisories list the corrected versions).
- If patching cannot be done immediately, disable or remove cups-browsed and block UDP port 631 and IPP browsing traffic at network boundaries.
- Restrict CUPS and IPP exposure to trusted networks only; do not expose port 631 to untrusted networks.
- Monitor vendor advisories for follow-up fixes, since this CVE is part of a multi-component chain.
- Treat any host running CUPS with browsing enabled as internet-exposed until verified patched.
Detection
- Audit hosts for cups-browsed and CUPS browsing services and confirm patched package versions of libcupsfilters, cups-filters, cups-browsed and libppd.
- Monitor network traffic for unexpected IPP responses or rogue IPP servers on UDP/TCP 631 reaching CUPS clients.
- Watch for anomalous child processes spawned by cupsd or cups-browsed, which would indicate post-exploitation activity.
- Review CUPS logs and PPD file creation events for unexpected or malformed printer attributes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-47076 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-47076), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.