CVE-2026-107655: NULL Pointer Dereference in Red Hat Red Hat Enterprise Linux 10
Description
A flaw was found in CUPS. When processing embedded job ticket comments within documents, the service improperly handles specific IPP attributes, causing an unhandled null pointer dereference. An unauthenticated attacker permitted to submit jobs to a shared printer queue can send a crafted Internet Printing Protocol (IPP) request to crash the print daemon, resulting in a temporary Denial of Service (DoS) for all printing services.
CVSS v3.1
Score 4.0medium
Affected software
Red Hat
Red Hat Enterprise Linux 10
Red Hat
Red Hat Enterprise Linux 6
Red Hat
Red Hat Enterprise Linux 7
Red Hat
Red Hat Enterprise Linux 8
Red Hat
Red Hat Enterprise Linux 9
Red Hat
Red Hat Hardened Images
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in CUPS arises when the print service improperly handles certain Internet Printing Protocol (IPP) attributes embedded in job ticket comments, leading to an unhandled NULL pointer dereference. Exploitation requires the attacker to be able to submit jobs to a shared printer queue but does not require authentication. Successful exploitation causes the print daemon to crash, temporarily disrupting all printing services on the affected system.
Potential Impact
An unauthenticated attacker with the ability to submit print jobs to a shared printer queue can cause a denial of service by crashing the print daemon. This results in temporary unavailability of printing services but does not impact confidentiality or integrity.
Mitigation Recommendations
Patch status is not yet confirmed — check the Red Hat vendor advisory at https://access.redhat.com/security/cve/CVE-2026-107655 for current remediation guidance.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- redhat
- Date Reserved
- 2026-10-08T14:31:11.612Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Vendor Advisory Urls
- [{"url":"https://access.redhat.com/security/cve/CVE-2026-107655","vendor":"Red Hat"}]
Threat ID: 6ac8b1b72cdf04f65644402f
Added to database: 10/09/2026, 09:19:51 UTC
Last enriched: 10/09/2026, 09:33:24 UTC
Last updated: 10/09/2026, 22:44:46 UTC
Views: 20
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.