mirror of
https://gitlab.com/buildroot.org/buildroot.git
synced 2026-09-10 00:04:06 -09:00
For more information about the release, see:
- https://github.com/OpenPrinting/cups/releases/tag/v2.4.17
- https://github.com/OpenPrinting/cups/blob/2.4.x/CHANGES.md
The new release 2.4.17 contains the following security fixes:
- CVE-2026-27447: The scheduler treated local user and group names as
case-insensitive.
https://www.cve.org/CVERecord?id=CVE-2026-27447
- CVE-2026-34978: The RSS notifier could write outside the scheduler's
RSS directory.
https://www.cve.org/CVERecord?id=CVE-2026-34978
- CVE-2026-34979: The scheduler did not always allocate enough memory
for a job's options string.
https://www.cve.org/CVERecord?id=CVE-2026-34979
- CVE-2026-34980: The scheduler did not filter control characters from
option values.
https://www.cve.org/CVERecord?id=CVE-2026-34980
- CVE-2026-34990: The scheduler incorrectly allowed local certificates
over the loopback interface.
https://www.cve.org/CVERecord?id=CVE-2026-34990
- CVE-2026-39314: Fixed the range check for job password strings.
https://www.cve.org/CVERecord?id=CVE-2026-39314
- CVE-2026-39316: Fixed a printer subscription bug in the scheduler.
https://www.cve.org/CVERecord?id=CVE-2026-39316
- CVE-2026-41079: Fixed a SNMP string conversion bug in the backends.
https://www.cve.org/CVERecord?id=CVE-2026-41079
Also updated patch offsets.
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
Signed-off-by: Julien Olivain <ju.o@free.fr>
(cherry picked from commit 1f801dc616)
Signed-off-by: Thomas Perale <thomas.perale@mind.be>
5 lines
285 B
Plaintext
5 lines
285 B
Plaintext
# Locally calculated:
|
|
sha256 89c703238de210d4f4f4e5d4269e3d60c4b2f487aad75a8a1eaecd659e4d0b77 cups-2.4.17-source.tar.gz
|
|
sha256 cfc7749b96f63bd31c3c42b5c471bf756814053e847c10f3eb003417bc523d30 LICENSE
|
|
sha256 977206f041b9a6f47ac00531e1242c0fab7063da71178f8d868b167b70866b6d NOTICE
|