CVE-2025-57812
Description
CUPS is a standards-based, open-source printing system, and libcupsfilters contains the code of the filters of the former cups-filters package as library functions to be used for the data format conversion tasks needed in Printer Applications. In CUPS-Filters versions up to and including 1.28.17 and libscupsfilters versions 2.0.0 through 2.1.1, CUPS-Filters's imagetoraster filter has an out of bounds read/write vulnerability in the processing of TIFF image files. While the pixel buffer is allocated with the number of pixels times a pre-calculated bytes-per-pixel value, the function which processes these pixels is called with a size of the number of pixels times 3. When suitable inputs are passed, the bytes-per-pixel value can be set to 1 and bytes outside of the buffer bounds get processed. In order to trigger the bug, an attacker must issue a print job with a crafted TIFF file, and pass appropriate print job options to control the bytes-per-pixel value of the output format. They must choose a printer configuration under which the imagetoraster filter or its C-function equivalent cfFilterImageToRaster() gets invoked. The vulnerability exists in both CUPS-Filters 1.x and the successor library libcupsfilters (CUPS-Filters 2.x). In CUPS-Filters 2.x, the vulnerable function is _cfImageReadTIFF() in libcupsfilters. When this function is invoked as part of cfFilterImageToRaster(), the caller passes a look-up-table during whose processing the out of bounds memory access happens. In CUPS-Filters 1.x, the equivalent functions are all found in the cups-filters repository, which is not split into subprojects yet, and the vulnerable code is in _cupsImageReadTIFF(), which is called through cupsImageOpen() from the imagetoraster tool. A patch is available in commit b69dfacec7f176281782e2f7ac44f04bf9633cfa.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
9cpe:2.3:a:openprinting:cups-filters:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:openprinting:cups-filters:*:*:*:*:*:*:*:*range: <1.28.17
- (no CPE)range: <=1.28.17
cpe:2.3:a:openprinting:libcupsfilters:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:openprinting:libcupsfilters:*:*:*:*:*:*:*:*range: >=2.0.0,<2.1.1
- (no CPE)range: 2.0.0-2.1.1
- (no CPE)range: cups-filters <= 1.28.17
- osv-coords4 versionspkg:rpm/opensuse/cups-filters&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/cups-filters&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/cups-filters&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP7pkg:rpm/suse/cups-filters&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5
< 1.25.0-150200.3.25.1+ 3 more
- (no CPE)range: < 1.25.0-150200.3.25.1
- (no CPE)range: < 1.25.0-150200.3.25.1
- (no CPE)range: < 1.25.0-150200.3.25.1
- (no CPE)range: < 1.0.58-19.35.1
Patches
Vulnerability mechanics
References
6- github.com/OpenPrinting/libcupsfilters/commit/b69dfacec7f176281782e2f7ac44f04bf9633cfanvdPatch
- github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-jpxg-qc2c-hgv4nvdExploitVendor Advisory
- www.openwall.com/lists/oss-security/2025/11/12/1nvdMailing ListThird Party Advisory
- github.com/OpenPrinting/cups-filters/blob/3c58463e341b12c9d30d7d3807d2bac1bc595a78/cupsfilters/image-tiff.cnvdProduct
- github.com/OpenPrinting/cups-filters/blob/3c58463e341b12c9d30d7d3807d2bac1bc595a78/filter/imagetoraster.cnvdProduct
- github.com/OpenPrinting/libcupsfilters/blob/33421982e10f6a14bc0bab03b80c9cf4660e8d7d/cupsfilters/image-tiff.cnvdProduct
News mentions
0No linked articles in our index yet.