Skip to main content

CVE-2026-87875: Out-of-bounds Read in Red Hat Red Hat Hardened Images

0
Medium
Published: 09/09/2026 (09/09/2026, 16:06:27 UTC)
Source: GCVE Database
Vendor/Project: Red Hat
Product: Red Hat Hardened Images

Description

The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.

CVSS v3.1

Score 4.3medium

Attack Vector
Adjacent Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/13/2026, 00:41:31 UTC

Technical Analysis

The vulnerability exists in the cupsUTF32ToUTF8() function in CUPS's cups/transcode.c, which lacks a source-length bound, allowing a heap out-of-bounds read. This can be reached through SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled input. The issue is tracked as CWE-125 (Out-of-bounds Read). Red Hat released updated RPM packages (cups-2.4.19-4.1.hum1 and related) for Red Hat Hardened Images to fix this vulnerability. The fix is applied upstream and backported to the 2.4.x branch. No known exploits are reported in the wild.

Potential Impact

An attacker can cause a heap out-of-bounds read, potentially leaking sensitive information such as cryptographic keys or memory addresses, which could aid in bypassing protection mechanisms like ASLR. Additionally, the vulnerability may cause application crashes (denial of service). The confidentiality impact is rated low, with no integrity or availability impact beyond potential crashes.

Mitigation Recommendations

Red Hat has released updated RPM packages for Red Hat Hardened Images including CUPS components that fix this vulnerability. Users should apply these updates as per Red Hat's advisory instructions. No additional mitigations are indicated or required beyond applying the official fix.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:66600
Cve Count
1
State
PUBLISHED

Threat ID: 6aa5f00e55bf5e2cf5ef834a

Added to database: 09/13/2026, 00:36:30 UTC

Last enriched: 09/13/2026, 00:41:31 UTC

Last updated: 09/13/2026, 04:01:22 UTC

Views: 7

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses