Amazon Linux 2 (EOS) Security Advisory: ALAS2-2026-3901
Advisory Released Date: 2026-09-14
Advisory Updated Date: 2026-09-14
A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job. (CVE-2026-64612)
Affected Packages:
cups-filters
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update cups-filters or yum update --advisory ALAS2-2026-3901 to update your system.
aarch64:
cups-filters-1.0.35-26.amzn2.0.3.aarch64
cups-filters-libs-1.0.35-26.amzn2.0.3.aarch64
cups-filters-devel-1.0.35-26.amzn2.0.3.aarch64
cups-filters-debuginfo-1.0.35-26.amzn2.0.3.aarch64
i686:
cups-filters-1.0.35-26.amzn2.0.3.i686
cups-filters-libs-1.0.35-26.amzn2.0.3.i686
cups-filters-devel-1.0.35-26.amzn2.0.3.i686
cups-filters-debuginfo-1.0.35-26.amzn2.0.3.i686
src:
cups-filters-1.0.35-26.amzn2.0.3.src
x86_64:
cups-filters-1.0.35-26.amzn2.0.3.x86_64
cups-filters-libs-1.0.35-26.amzn2.0.3.x86_64
cups-filters-devel-1.0.35-26.amzn2.0.3.x86_64
cups-filters-debuginfo-1.0.35-26.amzn2.0.3.x86_64