CVE-2026-64611: Red Hat Enterprise Linux 10

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.

Affected products

  • Red Hat Red Hat Enterprise Linux 10: before 1:2.0.0-13.el10_2 (fixed in 1:2.0.0-13.el10_2)
  • Red Hat Red Hat Enterprise Linux 7
  • Red Hat Red Hat Enterprise Linux 8
  • Red Hat Red Hat Enterprise Linux 9

Published 2026-07-23. Last modified 2026-08-19.