Skip to finding
important · Privilege — Linux

cups2root converts delegated Ubuntu printer administration into an interactive root shell.

Affects

CUPS and cups-filters, the printing service and backend collection used on Ubuntu and other Linux/Unix systems.

A local lpadmin member can use the privileged serial backend to rewrite cups-files.conf, crash cupsd, and have systemd restart it with an attacker-controlled ServerBin path.

Detail and 2 sources

The restarted daemon executes a replacement cups-exec as root without leaving the CUPS AppArmor profile.

Public exploit code exists, the root shell was independently reproduced, and no upstream patch is identified.

Share this finding
Get it by email

The same brief, every morning. One email a day, nothing else.

Every finding here carries a source that was checked before it published. If something is wrong, write to admin@fullchain.sh — corrections are published on the day they affect.

Sunday, September 20, 2026