PT-2025-46687 · Unknown+4 · Libcupsfilters+5

Published

2025-11-12

·

Updated

2026-01-20

·

CVE-2025-57812

CVSS v3.1

3.7

Low

VectorAV:A/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions CUPS-Filters versions up to and including 1.28.17 libcupsfilters versions 2.0.0 through 2.1.1
Description CUPS is a standards-based, open-source printing system, and libcupsfilters contains the code of the filters of the former cups-filters package as library functions. The imagetoraster filter has an out-of-bounds read/write issue in the processing of TIFF image files. This occurs because the pixel buffer is allocated with a pre-calculated bytes-per-pixel value, but the processing function is called with a size based on three times the number of pixels. This allows processing of bytes outside the buffer bounds when the bytes-per-pixel value is set to 1. An attacker can trigger this by issuing a print job with a crafted TIFF file and controlling the bytes-per-pixel value of the output format. The vulnerable function in CUPS-Filters 2.x is cfImageReadTIFF() within cfFilterImageToRaster(), and in CUPS-Filters 1.x, it is cupsImageReadTIFF() called through cupsImageOpen() from the imagetoraster tool.
Recommendations CUPS-Filters versions up to and including 1.28.17 should be updated. libcupsfilters versions 2.0.0 through 2.1.1 should be updated.

Exploit

Fix

RCE

DoS

Out of bounds Read

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2025-15977
CVE-2025-57812
DLA-4380-1
GHSA-JPXG-QC2C-HGV4
MGASA-2025-0304
RHSA-2026:8814
SUSE-SU-2025:4158-1
SUSE-SU-2025:4198-1
SUSE-SU-2025_4158-1
SUSE-SU-2025_4198-1
USN-7877-1
USN-7878-1

Affected Products

Cups-Filters
Debian
Linuxmint
Suse
Ubuntu
Libcupsfilters