CVE-2026-64611: Red Hat Enterprise Linux 10
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.
Affected products
- Red Hat Red Hat Enterprise Linux 10: before 1:2.0.0-13.el10_2 (fixed in 1:2.0.0-13.el10_2)
- Red Hat Red Hat Enterprise Linux 7
- Red Hat Red Hat Enterprise Linux 8
- Red Hat Red Hat Enterprise Linux 9
Published 2026-07-23. Last modified 2026-08-19.