PT-2025-46713 · Cups+5 · Cups+6

Published

2025-11-10

·

Updated

2026-01-20

·

CVE-2025-64503

CVSS v3.1

4.0

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions cups-filters versions prior to 1.28.18
Description cups-filters includes backends, filters, and other software needed for the CUPS printing service. A flaw exists where a specially crafted PDF file with a large MediaBox value can cause an out-of-bounds write in the pdftoraster tool within CUPS-Filter 1.x. This occurs due to an overflow in the calculation of bytesPerLine, leading to the allocation of a small lineBuf. Subsequently, the writePixel8 function attempts to write beyond the bounds of this buffer. The issue stems from a missing overflow check during the bytesPerLine multiplication.
Recommendations Update to cups-filters version 1.28.18 or later.

Exploit

Fix

Memory Corruption

Weakness Enumeration

Related Identifiers

BDU:2026-03141
CVE-2025-64503
DLA-4380-1
GHSA-893J-2WR2-WRH9
MGASA-2025-0304
RHSA-2026:8814
SUSE-SU-2025:4158-1
SUSE-SU-2025:4198-1
USN-7877-1
USN-7878-1

Affected Products

Cups
Debian
Linuxmint
Suse
Ubuntu
Cups-Filters
Pdftoraster