Bug 34900 - cups new security issues CVE-2025-58364 and CVE-2025-58060
Summary: cups new security issues CVE-2025-58364 and CVE-2025-58060
Status: RESOLVED FIXED
Alias: None
Product: Mageia
Classification: Unclassified
Component: Security (show other bugs)
Version: 9
Hardware: All Linux
Priority: Normal normal
Target Milestone: ---
Assignee: QA Team
QA Contact: Sec team
URL:
Whiteboard: MGA9-32-OK MGA9-64-OK
Keywords: advisory, validated_update
Depends on:
Blocks: 34800
  Show dependency treegraph
 
Reported: 2025-12-24 10:31 CET by Nicolas Salguero
Modified: 2026-01-15 10:00 CET (History)
6 users (show)

See Also:
Source RPM: cups-2.4.6-1.5.mga9
CVE: CVE-2025-58364, CVE-2025-58060
Status comment:


Attachments

Description Nicolas Salguero 2025-12-24 10:31:36 CET
Reference: https://lists.debian.org/debian-security-announce/2025/msg00162.html

When I looked for a fix for bug 34800, I found I missed those two CVEs.
Nicolas Salguero 2025-12-24 10:33:08 CET

CVE: (none) => CVE-2025-58364, CVE-2025-58060
Source RPM: (none) => cups-2.4.6-1.5.mga9
Depends on: (none) => 34800
Status comment: (none) => Patches available from Debian and Ubuntu

Comment 1 Morgan Leijström 2025-12-26 19:04:39 CET
Assigning to our registered cups maintainer.

CC: (none) => fri
Assignee: bugsquad => thierry.vignaud

Comment 2 Nicolas Salguero 2025-12-27 15:39:15 CET
Suggested advisory:
========================

The updated packages fix a regression and security vulnerabilities:

cups has Authentication bypass with AuthType Negotiate. (CVE-2025-58060)

cups: Remote DoS via null dereference. (CVE-2025-58364)

References:
https://lists.debian.org/debian-security-announce/2025/msg00162.html
https://bugs.mageia.org/show_bug.cgi?id=34800
========================

Updated packages in core/updates_testing:
========================
cups-2.4.6-1.6.mga9
cups-common-2.4.6-1.6.mga9
cups-filesystem-2.4.6-1.6.mga9
cups-printerapp-2.4.6-1.6.mga9
lib(64)cups2-2.4.6-1.6.mga9
lib(64)cups2-devel-2.4.6-1.6.mga9

from SRPM:
cups-2.4.6-1.6.mga9.src.rpm

Assignee: thierry.vignaud => qa-bugs
Status comment: Patches available from Debian and Ubuntu => (none)
Status: NEW => ASSIGNED

Comment 3 Morgan Leijström 2025-12-28 04:17:16 CET
OK here mga9-64, Plasma
Updated packages, watched in log that server was restarted.
Configured my new network printer using MCC, print test OK.
Comment 4 Herman Viaene 2025-12-28 11:07:26 CET
MGA9-64 server Plasma on Compaq H000SB.
No installation issues.
Used MCC - Hardware to remove my HP Envy 6022 AllinOne and reinstall it. Checked http://localhost:631/printers/? and find printer there. Scan works.

CC: (none) => herman.viaene

katnatek 2025-12-28 23:04:03 CET

Keywords: (none) => advisory

PC LX 2025-12-29 01:59:11 CET

CC: (none) => mageia

Comment 5 Thomas Andrews 2025-12-29 02:25:12 CET
Tested with an HP Color Laserjet Pro M254dw. Printed two test pages, one from the HP Device Manager, the other from MCC. Both were good.

Also printed a test page with the cups-pdf virtual printer to the desktop, learned it was set for US Legal paper, switched it to US Letter, and printed another test. Looks good.

Also printed a test page with Foolishness, my Dell Inspiron 5100 32-bit Xfce computer, with no issues.

Validating.

Whiteboard: (none) => MGA9-32-OK MGA9-64-OK
Keywords: (none) => validated_update
CC: (none) => andrewsfarm, sysadmin-bugs

Comment 6 katnatek 2026-01-02 18:00:13 CET
ping

Flags: (none) => need_info?(dan)

Comment 7 Dan Fandrich 2026-01-02 21:01:17 CET
This bug is blocked on bug 34800. If this package is supposed to be pushed now, that blocker needs to be changed/removed.

CC: (none) => dan

Comment 8 katnatek 2026-01-02 21:08:23 CET
(In reply to Dan Fandrich from comment #7)
> This bug is blocked on bug 34800. If this package is supposed to be pushed
> now, that blocker needs to be changed/removed.

I think the dependency is this bug blocks the other

https://bugs.mageia.org/show_bug.cgi?id=34800#c35
> cups-2.4.6-1.6.mga9 should solve that issue.  See bug 34900.

Depends on: 34800 => (none)
Blocks: (none) => 34800

katnatek 2026-01-02 21:09:09 CET

Flags: need_info?(dan) => (none)

Comment 9 Mageia Robot 2026-01-02 22:21:35 CET
An update for this issue has been pushed to the Mageia Updates repository.

https://advisories.mageia.org/MGASA-2026-0001.html

Status: ASSIGNED => RESOLVED
Resolution: (none) => FIXED

Comment 10 spammer 2026-01-15 09:24:28 CET Comment hidden (spam)

CC: (none) => vileamhealen

Morgan Leijström 2026-01-15 10:00:27 CET

CC: vileamhealen => (none)


Note You need to log in before you can comment on or make changes to this bug.