important · Privilege — Linux
cups2root converts delegated Ubuntu printer administration into an interactive root shell.
Affects
CUPS and cups-filters, the printing service and backend collection used on Ubuntu and other Linux/Unix systems.
A local lpadmin member can use the privileged serial backend to rewrite cups-files.conf, crash cupsd, and have systemd restart it with an attacker-controlled ServerBin path.
Detail and 2 sources
The restarted daemon executes a replacement cups-exec as root without leaving the CUPS AppArmor profile.
Public exploit code exists, the root shell was independently reproduced, and no upstream patch is identified.