Skip to content

Commit 66a1985

Browse files
committed
cups-2.4.20.md: Be more detailed
1 parent 01405b3 commit 66a1985

1 file changed

Lines changed: 7 additions & 3 deletions

File tree

‎contents/post/cups-2.4.20.md‎

Lines changed: 7 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -8,12 +8,16 @@ date: '2026-10-05'
88

99
CUPS 2.4.20 provides amount of bug fixes and security fixes:
1010

11-
Assigned ids:
11+
Assigned CVE ids:
1212
- CVE-2025-55480, CVE-2026-61702, CVE-2026-87875, CVE-2026-87876, CVE-2026-55453, CVE-2026-55467, CVE-2026-105326
1313

14-
Several fixes use GHSA id, because we changed policy for vulnerabilities with CVSS < 7.0 due long waiting time for ids from CNA, which we take as lower priority vulnerabilities.
14+
Several fixes use GHSA id of security advisory due long waiting time for CVE ids from CNA. Due our changed policy the fixes referencing GHSA id are for:
1515

16-
Issues requiring print admin rights for triggering them, or the issues where it is explicitly mentioned the advisory is security hardening, are not taken as vulnerability fixes.
16+
* vulnerabilities with CVSS < 7.0, which we take as lower priority vulnerabilities,
17+
* issues which require print admin rights for triggering them,
18+
* issues where its fix is security hardening patch/feature.
19+
20+
Per our security policy, issues which require print admin rights, or are security hardening patches, are not taken as vulnerability and they reference a security advisory due convenience.
1721

1822
More details in CHANGES.md.
1923

0 commit comments

Comments
 (0)