v2.4.20 - 2026-10-05 -------------------- - SECURITY-5.7: The scheduler did not open temporary PPD files in exclusive mode (CVE-2026-55480) - SECURITY-5.5: The scheduler did not remove all job status attributes from a job creation request (GHSA-7j85-5r23-xhvh) - SECURITY-5.3: The scheduler did not validate the request language value (CVE-2026-61702) - SECURITY-4.6: Attribute names were not validated as proper keyword values (GHSA-w9hj-hq9p-m7f6) - SECURITY-4.3: The `cupsUTF32toUTF8` function incorrectly treated UTF-32 values as 64-bit (CVE-2026-87875) - SECURITY-4.1: Held jobs for temporary print queues could crash the scheduler (GHSA-qqm8-4q5h-jg55) - SECURITY-3.3: The backend did not sanitize IPP attribute strings (CVE-2026-55453) - SECURITY-3.3: The scheduler did not filter out group separators from job submissions (GHSA-wjc4-qhjr-5m5x) - SECURITY-3.0: Quota and policy operations did not treat usernames as case- sensitive (CVE-2026-87876) - SECURITY-3.0: The scheduler's startup permission checks were vulnerable to TOU attacks (GHSA-gj33-wxpv-6fgg) - SECURITY-2.5: The scheduler did not sanitize fax numbers (CVE-2026-55467) - SECURITY-2.5: The 'mailto' notifier did not sanitize the recipient address provided to the sendmail command (CVE-2026-105326) - SECURITY-2.3: The scheduler could crash when modifying a class (GHSA-pwg4-pv39-8c22) - Increased the size of the SNMP supply name buffer used by the network backends (Issue #1604) - The USB backend now clears a halt on USB errors (Issue #1606) - Updated a few character tests for signed char platforms (Issue #1623) - Updated dateTime parsing in IPP files (Issue #1710) - Now explicitly limit IPP attribute names to 255 bytes (Issue #1694) - Added validation of IPP "printer-state-reasons" and "printer-mandatory-job-attributes" attributes (Issue #1632) - Added missing Set-Printer-Attributes policy to cupsd.conf. - Removed problematic debug printfs from `dnssd` backend. - Fixed mapping of standard PPD/PWG/legacy media size names to the local PPD size name (Issue #1375) - Fixed handling of multiple PPD: keywords from filters (Issue #1562, related to CVE-2026-34980) - Fixed handling of Kerberos user@REALM identities for user validation and quotas when StripUserDomain is not enabled (Issue #1584) - Fixed raster error reporting overflow (Issue #1607) - Fixed `cupsRasterInterpretPPD` handling of bad numbers (Issue #1608) - Fixed SNMP hex string debug output (Issue #1610) - Fixed some web interface bugs (Issue #1611) - Fixed some compression issues in the rastertoepson and rastertohp drivers (Issue #1613) - Fixed MIME `char` rule handling (Issue #1614) - Fixed duplicate local printers (Issue #1531, Issue #1586, Issue #1593, Issue #1620) - Fixed PPD cache memory leak (Issue #1629, Issue #1344) - Fixed escaping of spaces in option values (Issue #1630) - Fixed potential buffer overflow in `cupsCopyDestConflicts` (Issue #1631) - Fixed backchannel parsing bug in `commandtops` filter (Issue #1637) - Fixed section parsing in the web help indexing code (Issue #1641) - Fixed potential buffer overrun in rastertolabel filter (Issue #1644) - Fixed potential buffer overrun in rastertohp filter (Issue #1650) - Fixed media selection with a mix of PPD and IPP options (Issue #1651) - Fixed potential access of deleted IPP Everywhere printer (Issue #1655) - Fixed limiting of PPD custom number output for large numbers (Issue #1656) - Fixed a potential output length bug in the rastertohp driver (Issue #1658) - Fixed a potential buffer underflow buf in the `ippAdd/SetStringf(v)` functions (Issue #1664) - Fixed handling of TLS system priorities (Issue #1677) - Fixed D-Bus notification policy definition (Issue #1691) - Fixed raster fallback for IPP Everywhere printers (Issue #1703) - Fixed potential SNMP OID side-channel overflow (Issue #1719) - Fixed potential scheduler printer use-after-free bug (Issue #1722) - Fixed several issues reported by Coverity - Fixed case-sensitive PPD keyword comparisons when filtering keyword updates from filters. - Fixed potential buffer overrun in `cupsDoAuthentication`. v2.4.19 - 2026-04-27 -------------------- - Fixed a regression in shared printing from non-local accounts (Issue #1557, related to CVE-2026-27447) v2.4.18 - 2026-04-22 -------------------- - Fixed cupsd crash if user does not exist (Issue #1555, related to CVE-2026-27447) v2.4.17 - 2026-04-17 -------------------- v2.4.16 - 2025-12-04 -------------------- v2.4.15 - 2025-11-27 -------------------- v2.4.14 - 2025-09-11 -------------------- v2.4.13 - 2025-09-11 -------------------- v2.4.12 - 2025-04-08 -------------------- v2.4.11 - 2024-09-30 -------------------- v2.4.10 - 2024-06-18 -------------------- v2.4.9 - 2024-06-11 ------------------- v2.4.8 - 2024-04-26 ------------------- v2.4.7 - 2023-09-20 ------------------- v2.4.6 - 2023-06-22 ------------------- v2.4.5 - 2023-06-13 ------------------- v2.4.4 - 2023-06-06 ------------------- v2.4.3 - 2023-06-01 ------------------- v2.4.2 - 2022-05-26 ------------------- v2.4.1 - 2022-01-27 ------------------- v2.4.0 - 2021-11-29 ------------------- v2.4rc1 - 2021-11-12 -------------------- v2.4b1 - 2021-10-27 -------------------