Red HatCVE-2026-87875
Red Hat Enterprise Linux 10: out-of-bounds read
Medium4.3CVE-2026-87875 · Published Sep 9, 2026 · updated Sep 12, 2026
The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 6 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
| all versions | No fix yet | |
| Red Hat OpenShift Container Platform 4 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-125
- www.cve.org/CVERecord?id=CVE-2026-87875
- nvd.nist.gov/vuln/detail/CVE-2026-87875
- access.redhat.com/errata/RHSA-2026:66600
- access.redhat.com/security/cve/CVE-2026-87875
- bugzilla.redhat.com/show_bug.cgi?id=2530994
- github.com/OpenPrinting/cups/commit/0c6842fc615e8afa284136a092da8178abf5f142
- github.com/OpenPrinting/cups/commit/2b1dc178a2d2325135b855142e384f4e8c42d8e4
- github.com/OpenPrinting/cups/security/advisories/GHSA-559w-7676-3xrq
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 9 | Red Hat memcached cache plugin of the community: remote code execution | High8.1 | No fix yet |
| Sep 9 | Two case-insensitive comparisons on request-derived usernames outside the main... | Low3.0 | No fix yet |
| Sep 9 | A flaw was found in SSSD's IdP authentication provider | High7.5 | No fix yet |
| Sep 9 | Red Hat Ceph Storage 5: improper certificate validation | Medium6.8 | No fix yet |
| Sep 9 | Red Hat FreeIPA. An unauthenticated remote attacker: cross-site scripting | High8.1 | No fix yet |
| Sep 9 | Red Hat bubblewrap. During sandbox setup: link following | High8.8 | No fix yet |