CVE-2026-39316 is a use-after-free vulnerability in OpenPrinting CUPS versions 2.4.16 and prior, affecting the cupsd scheduler on Linux and Unix-like systems. The flaw occurs when temporary printers are automatically deleted without properly expiring associated subscriptions, leaving dangling pointers to freed heap memory that are subsequently dereferenced, causing denial of service and potential code execution through heap grooming techniques. The vulnerability carries a CVSS score of 6.2 (Medium) with local attack vector, low complexity, and no special privileges required. The impact is primarily denial of service through cupsd daemon crashes, though the potential for remote code execution exists under specific heap grooming conditions. The EPSS score of 0.00015 indicates this is not currently a high-priority threat compared to other CVEs. Exploitation status shows no active exploitation in the wild, as the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and has not attracted significant community attention. While proof-of-concept code for the denial of service condition could theoretically be developed, the attack requires local access and the elevated complexity of heap manipulation for code execution makes this a lower-priority remediation target for most organizations.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.4.16CPE matchmatch criteria | cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.