What is CVE-2026-64611?
A flaw in libcupsfilters allows an infinite loop in the cfIEEE1284NormalizeMakeModel() function when processing an IEEE-1284 device ID with an empty model field, leading to sustained CPU consumption. A network-adjacent attacker can exploit this by broadcasting malicious crafted packets, causing denial of service. Affected systems should apply the library update and implement network-level filtering until patched.
Azərbaycanca: libcupsfilters kitabxanasında boş model sahəsi olan IEEE-1284 cihaz ID-si emal edilərkən sonsuz dövr yaranması nəticəsində CPU-nun yüksək yüklənməsinə səbəb olan boşluq aşkarlanıb. Bu, şəbəkəyə yaxın təcavüzkara xüsusi hazırlanmış yayım paketləri göndərməklə xidmətin dayandırılmasına nail olmaq imkanı verir. Təsirə məruz qalan sistemlərdə zəiflik aradan qaldırılanadək şəbəkə səviyyəsində filtrasiya tətbiq edilməli və kitabxana yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-400
FAQ2
How can a network-adjacent attacker exploit CVE-2026-64611?
An attacker can broadcast malicious crafted packets, triggering an infinite loop in the libcupsfilters library and causing sustained CPU consumption.
What is a temporary mitigation for CVE-2026-64611?
Network-level filtering should be implemented on affected systems until the vulnerability is patched.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.