ALAS2-2026-3901


Amazon Linux 2 (EOS) Security Advisory: ALAS2-2026-3901
Advisory Released Date: 2026-09-14
Advisory Updated Date: 2026-09-14
Severity: Medium

Issue Overview:

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job. (CVE-2026-64612)


Affected Packages:

cups-filters


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update cups-filters or yum update --advisory ALAS2-2026-3901 to update your system.

New Packages:
aarch64:
    cups-filters-1.0.35-26.amzn2.0.3.aarch64
    cups-filters-libs-1.0.35-26.amzn2.0.3.aarch64
    cups-filters-devel-1.0.35-26.amzn2.0.3.aarch64
    cups-filters-debuginfo-1.0.35-26.amzn2.0.3.aarch64

i686:
    cups-filters-1.0.35-26.amzn2.0.3.i686
    cups-filters-libs-1.0.35-26.amzn2.0.3.i686
    cups-filters-devel-1.0.35-26.amzn2.0.3.i686
    cups-filters-debuginfo-1.0.35-26.amzn2.0.3.i686

src:
    cups-filters-1.0.35-26.amzn2.0.3.src

x86_64:
    cups-filters-1.0.35-26.amzn2.0.3.x86_64
    cups-filters-libs-1.0.35-26.amzn2.0.3.x86_64
    cups-filters-devel-1.0.35-26.amzn2.0.3.x86_64
    cups-filters-debuginfo-1.0.35-26.amzn2.0.3.x86_64