PatchSiren cyber security CVE debrief
CVE-2026-64611 Red Hat CVE debrief
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T11:16:40.680Z and has not been modified since then. The vulnerability affects libcupsfilters, specifically the cfIEEE1284NormalizeMakeModel() function, which enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field. This leads to sustained CPU consumption and potential denial of service. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement. Organizations using libcupsfilters should prioritize patching to prevent potential denial of service attacks. Affected operators and platforms should review compensating controls and implement monitoring for suspicious printer advertisements.
- Vendor
- Red Hat
- Product
- Red Hat Enterprise Linux 10
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-23
- Original CVE updated
- 2026-08-13
- Advisory published
- 2026-07-23
- Advisory updated
- 2026-08-13
Who should care
Organizations using libcupsfilters, network administrators, and security teams responsible for patch management and vulnerability mitigation should prioritize patching to prevent potential denial of service attacks. Affected operators and platforms should review compensating controls and implement monitoring for suspicious printer advertisements.
Technical summary
The cfIEEE1284NormalizeMakeModel() function in libcupsfilters enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field. This leads to sustained CPU consumption and potential denial of service. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement. The vulnerability affects libcupsfilters and could impact network-adjacent systems.
Defensive priority
Organizations using libcupsfilters should prioritize patching to prevent potential denial of service attacks.
Recommended defensive actions
- Apply patches for libcupsfilters as soon as available
- Monitor network-adjacent printer advertisements for suspicious activity
- Implement compensating controls to limit denial of service impact
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE-2026-64611 flaw in libcupsfilters causes an infinite loop in the cfIEEE1284NormalizeMakeModel() function when processing a printer-advertised IEEE-1284 device ID with an empty model field. Evidence is based on CVE and NVD records, as well as references from Redhat. Affected product deployments should be reviewed for exposure, and defenders should verify patch applicability and system logs for signs of exploitation. Compensating controls may be necessary for exposed systems.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-23T11:16:40.680Z and has not been modified since then.