>

CUPS RCE: The Linux Printing Story That Went Viral Before CVEs Landed

In late September 2024, researcher Simone Margaritelli disclosed a chain of CUPS vulnerabilities — CVE-2024-47076, CVE-2024-47176 and siblings — allowing same-network attackers to register malicious printers and achieve code execution as the lp user via broadcast-trusting auto-configuration. Preceded by a hype-teaser countdown that split the community, the episode became the year's clearest study in disclosure-process dysfunction, severity theater, and the quiet ubiquity of trust-the-LAN daemons. This account covers the chain mechanics, the honest exposure math, and what to disable today.

Continue ReadingCUPS RCE: The Linux Printing Story That Went Viral Before CVEs Landed
>