Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-58364

26
FAUCET Score

CVE-2025-58364 is a remote Denial of Service (DoS) vulnerability affecting OpenPrinting CUPS versions 2.4.12 and earlier, caused by unsafe deserialization and validation of printer attributes leading to a null dereference in the libcups library. This vulnerability allows an attacker on the local subnet to crash CUPS and cups-browsed services on affected Linux machines. With a CVSS score of 6.5 (Medium), it has an Adjacent attack vector and low attack complexity, resulting in high availability impact. There is currently no public exploit code available, nor any evidence of active exploitation or significant community discussion.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.4.13CPE matchmatch criteria
cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
ADJACENT_NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.06%
Probability of exploitation in next 30 days
EPSS Percentile
61.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0106 is in the 90th percentile among its peer group of 1,802 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: cbl2 cups 2.3.3op2-9 on CBL Mariner 2.0Fixed in: 2.3.3op2-10
microsoftpatch availablevia msrc
Product: 17722-17084Fixed in: 2.4.13-1
microsoftpatch availablevia msrc
Product: 19950-17086Fixed in: 2.3.3op2-10
microsoftpatch availablevia msrc
Product: azl3 cups 2.4.10-1 on Azure Linux 3.0Fixed in: 2.4.13-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsFixed in: cups-1:2.3.3op2-16.el9_2.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.4 Extended Update SupportFixed in: cups-1:2.3.3op2-27.el9_4.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: cups-1:2.2.6-64.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: cups-1:2.3.3op2-33.el9_6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsFixed in: cups-1:2.3.3op2-13.el9_0.4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: cups-1:2.4.10-11.el10_0.1
View patch
grafanavendor investigatingvia llm_extracted
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: cups
redhatvendor investigatingvia redhat_api
Product: Red Hat OpenShift Container Platform 4Fixed in: rhcos

Vendor Advisories (3)

grafanallm-grafana-3bfe68bd8f94bc6dCRITICAL

HP ThinPro 8.1 SP9 Security Updates

Feb 2, 2026
redhatCVE-2025-58364Moderate

cups: Null Pointer Dereference in CUPS ipp_read_io() Leading to Remote DoS

Sep 11, 2025
microsoft2025-Sep/CVE-2025-58364

cups: Remote DoS via null dereference

Sep 9, 2025

References

lists.debian.org / debian-lts-announce/2025/09/msg00013.html
openwall.com / lists/oss-security/2025/09/11/2
github.com / OpenPrinting/cups/commit/e58cba9d6fceed4242980e51dbd1302cf638ab1d
Patch
github.com / OpenPrinting/cups/security/advisories/GHSA-7qx3-r744-6qv4
ExploitVendor Advisory