ALAS2023-2026-2127


Amazon Linux 2023 Security Advisory: ALAS2023-2026-2127
Advisory Released Date: 2026-09-14
Advisory Updated Date: 2026-09-14
Severity: Medium

Issue Overview:

A flaw was found in libcupsfilters and cups-filters. The PNG image reading function creates a libpng reader without installing an error recovery handler, causing the CUPS image filter process to abort when processing a malformed PNG file. An unauthenticated attacker could exploit this by submitting a specially crafted PNG print job, leading to denial of service of the in-flight print job. (CVE-2026-64612)


Affected Packages:

cups-filters


Issue Correction:
Run dnf update cups-filters --releasever 2023.12.20260914 or dnf update --advisory ALAS2023-2026-2127 --releasever 2023.12.20260914 to update your system.
More information on how to update your system can be found on this page: Amazon Linux 2023 documentation

New Packages:
aarch64:
    cups-filters-libs-debuginfo-1.28.16-3.amzn2023.0.6.aarch64
    cups-filters-libs-1.28.16-3.amzn2023.0.6.aarch64
    cups-filters-devel-1.28.16-3.amzn2023.0.6.aarch64
    cups-filters-debugsource-1.28.16-3.amzn2023.0.6.aarch64
    cups-filters-1.28.16-3.amzn2023.0.6.aarch64
    cups-filters-debuginfo-1.28.16-3.amzn2023.0.6.aarch64

src:
    cups-filters-1.28.16-3.amzn2023.0.6.src

x86_64:
    cups-filters-debugsource-1.28.16-3.amzn2023.0.6.x86_64
    cups-filters-libs-debuginfo-1.28.16-3.amzn2023.0.6.x86_64
    cups-filters-devel-1.28.16-3.amzn2023.0.6.x86_64
    cups-filters-libs-1.28.16-3.amzn2023.0.6.x86_64
    cups-filters-debuginfo-1.28.16-3.amzn2023.0.6.x86_64
    cups-filters-1.28.16-3.amzn2023.0.6.x86_64