Get real-time updates on Telegram
CVE-2021-25317: cups before 1.3.9 (exclusive), before 2.2.7 (exclusive), before 1.7.5 (exclusive) (+1 more affected versions); +6 more…
CVE-2021-25317. CVSS 3.1 base score 3.3 (LOW, NVD). EPSS 0.00268 (percentile 0.17398), scored 2026-10-08.
Affected technology
cups · before 1.3.9 (exclusive)
suse
fedora · 32
fedoraproject
fedora · 33
fedoraproject
fedora · 34
fedoraproject
cups · before 2.2.7 (exclusive)
suse
cups · before 1.7.5 (exclusive)
suse
cups · through 2.3.3op2-2.1 (inclusive)
suse
SUSE Linux Enterprise Server 11-SP4-LTSS · cups to before 1.3.9
SUSE
SUSE Manager Server 4.0 · cups to before 2.2.7
SUSE
SUSE OpenStack Cloud Crowbar 9 · cups to before 1.7.5
SUSE
openSUSE Leap 15.2 · cups to before 2.2.7
openSUSE
Factory · cups through 2.3.3op2-2.1
openSUSE
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 3.1): Local · Low privileges required · No user interaction required
Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · No user interaction required
What an attacker can do
Local attackers with control of the lp users can create files as root with 0644 permissions without the ability to set the content. Vendor/CNA’s CVSS 3.1 assessment (base score 3.3/10) rates confidentiality and availability impact as none; integrity impact as low. NVD’s CVSS 3.1 assessment (base score 3.3/10) rates confidentiality and availability impact as none; integrity impact as low.
- CWE
- CWE-276
- CCR priority
- 13.3 /100 (P5)
- CVSS 3.1
- 3.3 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N · NVD
- EPSS
- 0.00268 · percentile 0.17398 · 2026-10-08
- KEV
- no
Provenance
- GitHub Advisory Database · Source record · observed 2026-10-09 03:17:07.463462+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-09 03:13:32.966430+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2021-25317.html