CVE-2026-87875: Out-of-bounds Read in Red Hat Red Hat Hardened Images
The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
AI Analysis
Technical Summary
The vulnerability exists in the cupsUTF32ToUTF8() function in CUPS's cups/transcode.c, which lacks a source-length bound, allowing a heap out-of-bounds read. This can be reached through SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled input. The issue is tracked as CWE-125 (Out-of-bounds Read). Red Hat released updated RPM packages (cups-2.4.19-4.1.hum1 and related) for Red Hat Hardened Images to fix this vulnerability. The fix is applied upstream and backported to the 2.4.x branch. No known exploits are reported in the wild.
Potential Impact
An attacker can cause a heap out-of-bounds read, potentially leaking sensitive information such as cryptographic keys or memory addresses, which could aid in bypassing protection mechanisms like ASLR. Additionally, the vulnerability may cause application crashes (denial of service). The confidentiality impact is rated low, with no integrity or availability impact beyond potential crashes.
Mitigation Recommendations
Red Hat has released updated RPM packages for Red Hat Hardened Images including CUPS components that fix this vulnerability. Users should apply these updates as per Red Hat's advisory instructions. No additional mitigations are indicated or required beyond applying the official fix.
CVE-2026-87875: Out-of-bounds Read in Red Hat Red Hat Hardened Images
Description
The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
CVSS v3.1
Score 4.3medium
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in the cupsUTF32ToUTF8() function in CUPS's cups/transcode.c, which lacks a source-length bound, allowing a heap out-of-bounds read. This can be reached through SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled input. The issue is tracked as CWE-125 (Out-of-bounds Read). Red Hat released updated RPM packages (cups-2.4.19-4.1.hum1 and related) for Red Hat Hardened Images to fix this vulnerability. The fix is applied upstream and backported to the 2.4.x branch. No known exploits are reported in the wild.
Potential Impact
An attacker can cause a heap out-of-bounds read, potentially leaking sensitive information such as cryptographic keys or memory addresses, which could aid in bypassing protection mechanisms like ASLR. Additionally, the vulnerability may cause application crashes (denial of service). The confidentiality impact is rated low, with no integrity or availability impact beyond potential crashes.
Mitigation Recommendations
Red Hat has released updated RPM packages for Red Hat Hardened Images including CUPS components that fix this vulnerability. Users should apply these updates as per Red Hat's advisory instructions. No additional mitigations are indicated or required beyond applying the official fix.
Technical Details
- Gcve Source
- db.gcve.eu
- Csaf Category
- csaf_security_advisory
- Csaf Version
- 2.0
- Publisher
- Red Hat Product Security
- Advisory Id
- RHSA-2026:66600
- Cve Count
- 1
- State
- PUBLISHED
Threat ID: 6aa5f00e55bf5e2cf5ef834a
Added to database: 09/13/2026, 00:36:30 UTC
Last enriched: 09/13/2026, 00:41:31 UTC
Last updated: 09/13/2026, 04:01:22 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.