Bug 33293 - cups new security issue CVE-2024-35235
Summary: cups new security issue CVE-2024-35235
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-64-OK, MGA9-32-OK
Keywords: advisory, validated_update
Depends on:
Blocks:
 
Reported: 2024-06-12 11:17 CEST by Nicolas Salguero
Modified: 2024-06-17 19:45 CEST (History)
8 users (show)

See Also:
Source RPM: cups-2.4.8-1.mga10.src.rpm
CVE: CVE-2024-35235
Status comment: Patch available from upstream


Attachments

Description Nicolas Salguero 2024-06-12 11:17:25 CEST
That CVE was announced here:
https://www.openwall.com/lists/oss-security/2024/06/11/1

The fix is:
https://github.com/OpenPrinting/cups/commit/a436956f3

Mageia 9 is also affected.
Nicolas Salguero 2024-06-12 11:18:08 CEST

Status comment: (none) => Patch available from upstream
CVE: (none) => CVE-2024-35235
Source RPM: (none) => cups-2.4.8-1.mga10.src.rpm
Whiteboard: (none) => MGA9TOO

Comment 1 David GEIGER 2024-06-13 07:16:34 CEST
Packages in 9/Core/Updates_testing:
======================
cups-2.4.6-1.2.mga9
cups-common-2.4.6-1.2.mga9
cups-filesystem-2.4.6-1.2.mga9.noarch.rpm
cups-printerapp-2.4.6-1.2.mga9
libcups2-2.4.6-1.2.mga9
libcups2-devel-2.4.6-1.2.mga9
lib64cups2-2.4.6-1.2.mga9
lib64cups2-devel-2.4.6-1.2.mga9

From SRPMS:
cups-2.4.6-1.2.mga9.src.rpm

CC: (none) => geiger.david68210
Whiteboard: MGA9TOO => (none)
Version: Cauldron => 9
Assignee: bugsquad => qa-bugs

katnatek 2024-06-13 20:00:31 CEST

Keywords: (none) => advisory

Comment 2 Tony Blackwell 2024-06-13 23:24:37 CEST
not yet in M9 core-updates-testing

CC: (none) => tablackwell

Comment 3 katnatek 2024-06-14 03:16:09 CEST
RH mageia 9 x86_64

LC_ALL=C urpmi --auto --auto-update
medium "QA Testing (64-bit)" is up-to-date
medium "QA Testing (32-bit)" is up-to-date
medium "Core Release (distrib1)" is up-to-date
medium "Core Updates (distrib3)" is up-to-date
medium "Nonfree Release (distrib11)" is up-to-date
medium "Nonfree Updates (distrib13)" is up-to-date
medium "Tainted Release (distrib21)" is up-to-date
medium "Tainted Updates (distrib23)" is up-to-date
medium "Core 32bit Release (distrib31)" is up-to-date
medium "Core 32bit Updates (distrib32)" is up-to-date
medium "Nonfree 32bit Release (distrib36)" is up-to-date
medium "Tainted 32bit Release (distrib41)" is up-to-date
medium "Tainted 32bit Updates (distrib42)" is up-to-date
medium "BDK-Free-x86_64" is up-to-date
medium "BDK-Free-noarch" is up-to-date
medium "BDK-NonFree-x86_64" is up-to-date


installing cups-filesystem-2.4.6-1.2.mga9.noarch.rpm lib64cups2-2.4.6-1.2.mga9.x86_64.rpm cups-2.4.6-1.2.mga9.x86_64.rpm cups-common-2.4.6-1.2.mga9.x86_64.rpm from //home/katnatek/qa-testing/x86_64
Preparing...                     ##################################################################################################
      1/4: lib64cups2            ##################################################################################################
      2/4: cups-common           ##################################################################################################
      3/4: cups-filesystem       ##################################################################################################
      4/4: cups                  ##################################################################################################
      1/4: removing cups-2.4.6-1.1.mga9.x86_64
                                 ##################################################################################################
      2/4: removing cups-filesystem-2.4.6-1.1.mga9.noarch
                                 ##################################################################################################
      3/4: removing cups-common-2.4.6-1.1.mga9.x86_64

systemctl restart cups.service 
systemctl -l status cups.service 
● cups.service - CUPS Scheduler
     Loaded: loaded (/usr/lib/systemd/system/cups.service; disabled; preset: disabled)
     Active: active (running) since Thu 2024-06-13 19:14:56 CST; 11s ago
TriggeredBy: ● cups.socket
       Docs: man:cupsd(8)
   Main PID: 72835 (cupsd)
     Status: "Scheduler is running..."
      Tasks: 2 (limit: 6904)
     Memory: 1.8M
        CPU: 14ms
     CGroup: /system.slice/cups.service
             └─72835 /usr/sbin/cupsd -l

jun 13 19:14:56 jgrey.phoenix systemd[1]: Starting cups.service...
jun 13 19:14:56 jgrey.phoenix systemd[1]: Started cups.service.

                                 ##################################################################################################
      4/4: removing lib64cups2-2.4.6-1.1.mga9.x86_64
                                 ##################################################################################################

No printers to test
Comment 4 Ben McMonagle 2024-06-14 03:47:53 CEST
x86_64

applied update

printed a web page to network printer -ok

CC: (none) => westel

Comment 5 Morgan Leijström 2024-06-14 11:39:50 CEST
x86_64 Plasma X11  here.
Printed pdf:s opened in Firefox and Thunderbird to Boomaga and network printer.
Printed from LibreOffice calc to Boomaga.

CC: (none) => fri

Comment 6 PC LX 2024-06-14 19:50:47 CEST
Installed and tested without issues.

Printer: HP Officejet 4658
System: Mageia 9, x86_64, Plasma DE, AMD Ryzen 5 5600G with Radeon Graphics using amdgpu driver.


Tested:
- printing from multiple applications (e.g. Firefox, Kate, Okular, KWrite, LibreOffice Writer);
- HP Device Manager (seeing status, ink supplies, print test page);
- scanning using XSane;


All worked as usual.



$ uname -a
Linux jupiter 6.6.28-desktop-1.mga9 #1 SMP PREEMPT_DYNAMIC Wed Apr 17 17:19:36 UTC 2024 x86_64 GNU/Linux
$ rpm -qa | grep -P 'cups.*-2.4.6-' | sort
cups-2.4.6-1.2.mga9
cups-common-2.4.6-1.2.mga9
cups-filesystem-2.4.6-1.2.mga9
lib64cups2-2.4.6-1.2.mga9
$ rpm -qa | grep cups | sort
cups-2.4.6-1.2.mga9
cups-common-2.4.6-1.2.mga9
cups-drivers-foo2zjs-0.0-1.20121012.14.mga9
cups-filesystem-2.4.6-1.2.mga9
cups-filters-1.28.16-6.mga9
cups-pk-helper-0.2.7-1.mga9
gutenprint-cups-5.3.4-4.mga9
lib64cups2-2.4.6-1.2.mga9
lib64cups-filters1-1.28.16-6.mga9
python3-cups-2.0.1-4.mga9

CC: (none) => mageia

Comment 7 Herman Viaene 2024-06-15 12:00:54 CEST
MGA9-64 Plasma Wayland on HP-Pavillion.
No installation issues.
Deleted existing HP Envy 6022 allinone printer from MCC - Hardware - Printer.
Strange: still works as scanner.
Added printer again in MCC, autodetection worked, printed test page an scanner, all work OK.

CC: (none) => herman.viaene

Comment 8 Tony Blackwell 2024-06-15 23:44:28 CEST
M9 x86_64.  Working fine with HJP Officejet Pro 8600 Plus multi-function printers.
Comment 9 Tony Blackwell 2024-06-15 23:45:31 CEST
s/HJP/HP
Comment 10 Morgan Leijström 2024-06-16 00:25:57 CEST
Printing being important functionality, I think a 32 bit test would be good.

Whiteboard: (none) => MGA9-64-OK

Comment 11 Ben McMonagle 2024-06-16 05:25:42 CEST
i586

install packages:
cups-2.4.6-1.2.mga9
cups-common-2.4.6-1.2.mga9
cups-filesystem-2.4.6-1.2.mga9.noarch.rpm
cups-printerapp-2.4.6-1.2.mga9
libcups2-2.4.6-1.2.mga9

setup network printer (kyocera colour laser)

printed this webpage -ok
Ben McMonagle 2024-06-16 05:27:08 CEST

Whiteboard: MGA9-64-OK => MGA9-64-OK | MGA9-32-OK

katnatek 2024-06-16 05:30:59 CEST

CC: (none) => andrewsfarm

katnatek 2024-06-16 05:31:13 CEST

Whiteboard: MGA9-64-OK | MGA9-32-OK => MGA9-64-OK,MGA9-32-OK

Comment 12 Morgan Leijström 2024-06-16 08:10:10 CEST
Thank you

Whiteboard: MGA9-64-OK,MGA9-32-OK => MGA9-64-OK, MGA9-32-OK
Keywords: (none) => validated_update
CC: (none) => sysadmin-bugs

Comment 13 Mageia Robot 2024-06-17 19:45:00 CEST
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2024-0227.html

Resolution: (none) => FIXED
Status: NEW => RESOLVED


Note You need to log in before you can comment on or make changes to this bug.