Rapid7’s 2026 Global Cybersecurity Summit is now available on-demand.Watch sessions.
Rapid7

vulnerability

Amazon Linux AMI 2: CVE-2021-25317: Security patch for cups (Multiple Advisories)

Severity
2
CVSS
(AV:L/AC:L/Au:N/C:N/I:P/A:N)
Published
May 5, 2021
Added
Aug 21, 2024
Modified
May 20, 2026

Description

A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS cups versions prior to 1.3.9. SUSE Manager Server 4.0 cups versions prior to 2.2.7. SUSE OpenStack Cloud Crowbar 9 cups versions prior to 1.7.5. openSUSE Leap 15.2 cups versions prior to 2.2.7. openSUSE Factory cups version 2.3.3op2-2.1 and prior versions.

Solutions

amazon-linux-ami-2-upgrade-cupsamazon-linux-ami-2-upgrade-cups-clientamazon-linux-ami-2-upgrade-cups-debuginfoamazon-linux-ami-2-upgrade-cups-develamazon-linux-ami-2-upgrade-cups-filesystemamazon-linux-ami-2-upgrade-cups-ipptoolamazon-linux-ami-2-upgrade-cups-libsamazon-linux-ami-2-upgrade-cups-lpd
Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.