Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2026-39316

22
FAUCET Score

CVE-2026-39316 is a use-after-free vulnerability in OpenPrinting CUPS versions 2.4.16 and prior, affecting the cupsd scheduler on Linux and Unix-like systems. The flaw occurs when temporary printers are automatically deleted without properly expiring associated subscriptions, leaving dangling pointers to freed heap memory that are subsequently dereferenced, causing denial of service and potential code execution through heap grooming techniques. The vulnerability carries a CVSS score of 6.2 (Medium) with local attack vector, low complexity, and no special privileges required. The impact is primarily denial of service through cupsd daemon crashes, though the potential for remote code execution exists under specific heap grooming conditions. The EPSS score of 0.00015 indicates this is not currently a high-priority threat compared to other CVEs. Exploitation status shows no active exploitation in the wild, as the vulnerability is not listed on CISA's Known Exploited Vulnerabilities catalog and has not attracted significant community attention. While proof-of-concept code for the denial of service condition could theoretically be developed, the attack requires local access and the elevated complexity of heap manipulation for code execution makes this a lower-priority remediation target for most organizations.

Impacted Technologies

VendorProductVersion(s)CPE
<= 2.4.16CPE matchmatch criteria
cpe:2.3:a:openprinting:cups:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

4.0MEDIUM

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
2.5
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.18%
Probability of exploitation in next 30 days
EPSS Percentile
7.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0018 is in the 16th percentile among its peer group of 3,052 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (6)

microsoftpatch availablevia msrc
Product: azl3 cups 2.4.16-1 on Azure Linux 3.0Fixed in: 2.4.17-1
microsoftpatch availablevia msrc
Product: 20737-17084Fixed in: 2.4.17-1
ubuntupatch availablevia ubuntu_usn
Product: cups (jammy)Fixed in: 2.4.1op1-1ubuntu4.20
ubuntupatch availablevia ubuntu_usn
Product: cups (noble)Fixed in: 2.4.7-1.2ubuntu7.13
ubuntupatch availablevia ubuntu_usn
Product: cups (questing)Fixed in: 2.4.12-0ubuntu3.9
ubuntupatch availablevia ubuntu_usn
Product: cups (resolute)Fixed in: 2.4.16-1ubuntu1.2

Vendor Advisories (2)

ubuntuUSN-8405-1

CUPS vulnerabilities

Jun 8, 2026
microsoft2026-Apr/CVE-2026-39316Low

CUPS has a use-after-free in `cupsdDeleteTemporaryPrinters` via dangling subscription pointer

Apr 2, 2026

References

github.com / OpenPrinting/cups/security/advisories/GHSA-pjv5-prqp-46rg
ExploitMitigationVendor Advisory