MEDIUMVulnerability
CVE-2026-87875
The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a source-length bound and can read past the end of the source buffer, resulting in a heap out-of-bounds read. This is reachable via SNMP supply-description parsing in backend/snmp-supplies.c with attacker-controlled content.
Properties
- severity
- MEDIUM
- score
- 4.3
- cve_id
- CVE-2026-87875
- signal_observed_at
- 2026-09-17T21:32:24+00:00
- vector
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
- published_at
- 2026-09-09T17:17:53.240
- last_modified
- 2026-09-12T00:17:06.303
Related Entities (2)
HAS_WEAKNESS (1)
→[Weakness]Out-of-bounds Read
DESCRIBED_BY (1)
→[Source]NVD
Explore deeper with Ninja Signal's threat intelligence graph