← Vulnerability feed

Vulnerability record · CVE-2024-47076 · published 26 September 2024

CVE-2024-47076: libcupsfilters missing IPP attribute sanitization in cfGetPrinterAttributes5

Openprinting · Libcupsfilters

The cfGetPrinterAttributes5 function in libcupsfilters does not sanitize IPP attributes returned by an IPP server. When those attributes are consumed, for example to generate a PPD file, attacker-controlled data flows into the rest of the CUPS system. This is one component of the CUPS remote code execution chain disclosed in 2024, so it matters to any host running CUPS with cups-browsed or related browsing components.

8.6 CVSS 3.1 High EPSS 78% · top 0.4% CWE-20 · Improper input validation
8.6CVSS 3.1 base score
78%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
9References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

high priorityCVSS 8.6 with network reachability, no authentication or interaction, and very high EPSS plus public exploit references, though it is not in KEV and is one link in a chain rather than a standalone RCE.

What it is

The cfGetPrinterAttributes5 function in libcupsfilters does not sanitize IPP attributes returned by an IPP server. When those attributes are consumed, for example to generate a PPD file, attacker-controlled data flows into the rest of the CUPS system. This is one component of the CUPS remote code execution chain disclosed in 2024, so it matters to any host running CUPS with cups-browsed or related browsing components.

Impact

An attacker can inject arbitrary data into CUPS processing, which in the disclosed chain is used to achieve remote code execution on the affected host. On its own, the flaw gives an attacker control over data consumed by downstream CUPS components.

Attack surface

Reachable over the network with no authentication and no user interaction, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The attacker needs to be able to act as or spoof an IPP server that the CUPS client or browsing daemon contacts.

Exploitation

Not listed in CISA KEV, but EPSS is 0.77644 (99.54th percentile) and multiple references are tagged Exploit, including the vendor advisory and a third-party writeup. Public exploitation activity is therefore likely.

What to do

  • Apply the libcupsfilters patch (commit 95576ec3d20c109332d14672a807353cdc551018) and the coordinated cups-browsed, cups-filters and libppd fixes.
  • Update to the fixed packages from your distribution (Debian LTS advisory and vendor advisories list the corrected versions).
  • If patching cannot be done immediately, disable or remove cups-browsed and block UDP port 631 and IPP browsing traffic at network boundaries.
  • Restrict CUPS and IPP exposure to trusted networks only; do not expose port 631 to untrusted networks.
  • Monitor vendor advisories for follow-up fixes, since this CVE is part of a multi-component chain.
  • Treat any host running CUPS with browsing enabled as internet-exposed until verified patched.

Detection

  • Audit hosts for cups-browsed and CUPS browsing services and confirm patched package versions of libcupsfilters, cups-filters, cups-browsed and libppd.
  • Monitor network traffic for unexpected IPP responses or rogue IPP servers on UDP/TCP 631 reaching CUPS clients.
  • Watch for anomalous child processes spawned by cupsd or cups-browsed, which would indicate post-exploitation activity.
  • Review CUPS logs and PPD file creation events for unexpected or malformed printer attributes.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-47076 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

3.7CVE-2025-57812Openprinting cups-filters out-of-bounds read vulnerabilityCUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as…EPSS 0.45%3.3CVE-2025-64503Openprinting cups-filters out-of-bounds write vulnerabilitycups-filters contains backends, filters, and other software required to get the cups printing service working on operating systems other than macos. …EPSS 0.21%9.5CVE-2026-88771Citrix NetScaler Improper Input Validation VulnerabilityImproper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-…KEV9.5CVE-2026-93952Arista velocloud orchestrator improper input validation vulnerabilityVeloCloud Orchestrator (VCO) on-prem has a security issue where this issue may allow a remote attacker to access privileged internal functionality an…KEVEPSS 0.90%8.8CVE-2019-1068Microsoft SQL Server improper input validation remote code executionMicrosoft SQL Server mishandles processing of internal functions, allowing an authenticated remote attacker to execute code on the database server. T…KEVEPSS 58%analysed5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed9.3CVE-2026-12569PTC Windchill PDMlink and FlexPLM deserialization RCEPTC Windchill PDMlink and FlexPLM contain a deserialization of untrusted data flaw (also classified as improper input validation) that allows remote …KEVEPSS 46%analysed10.0CVE-2026-34910Ubiquiti UniFi OS input validation flaw allows command injectionUniFi OS devices contain an improper input validation vulnerability (CWE-20) that lets a network-reachable attacker inject and execute commands. It a…KEVEPSS 46%analysed

Source: NIST National Vulnerability Database (record CVE-2024-47076), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.