Skip to content
Ubuntu 16.04 CUPS Critical Control Character Injection CVE-2026

Ubuntu 16.04 CUPS Critical Control Character Injection CVE-2026

Linuxsecurity LinuxSecurity Advisories July 21, 2026

Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges ×

CUPS could be made to run programs as the lp user if it received specially crafted print job requests. Software Description: - cups: Common UNIX Printing System(tm) Details: It was discovered that CUPS did not properly filter control characters in IPP string attributes and PPD keywords. An unauthenticated attacker could exploit this to execute arbitrary code as the lp user on systems with shared target queues.

CUPS could be made to run programs as the lp user if it received specially crafted print job requests.

Software Description:

- cups: Common UNIX Printing System(tm)

It was discovered that CUPS did not properly filter control characters in IPP string attributes and PPD keywords. An unauthenticated attacker could exploit this to execute arbitrary code as the lp user on systems with shared target queues.

The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 LTS cups 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro cups-bsd 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro cups-client 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro cups-common 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro cups-core-drivers 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro cups-daemon 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro libcups2 2.1.3-4ubuntu0.11+esm13 Available with Ubuntu Pro In general, a standard system update will make all the necessary changes.

Ubuntu Security Notice USN-8578-1

Get the latest Linux and open source security news straight to your inbox.

Extracted Entities

Companies (1)

Platforms (2)