cups: ownership of /var/log/cups allows the lp user to create files as root
Published May 5, 2021
3.3
LOWCVSS 3.1
EPSS 0.27%
Description
A Incorrect Default Permissions vulnerability in the packaging of cups of SUSE Linux Enterprise Server 11-SP4-LTSS, SUSE Manager Server 4.0, SUSE OpenStack Cloud Crowbar 9; openSUSE Leap 15.2, Factory allows local attackers with control of the lp users to create files as root with 0644 permissions without the ability to set the content. This issue affects: SUSE Linux Enterprise Server 11-SP4-LTSS cups versions prior to 1.3.9. SUSE Manager Server 4.0 cups versions prior to 2.2.7. SUSE OpenStack Cloud Crowbar 9 cups versions prior to 1.7.5. openSUSE Leap 15.2 cups versions prior to 2.2.7. openSUSE Factory cups version 2.3.3op2-2.1 and prior versions.
Affected products
-
- Version cupsStatusaffectedConstraints<1.3.9
- Version
-
- Version cupsStatusaffectedConstraints<2.2.7
- Version
-
- Version cupsStatusaffectedConstraints<1.7.5
- Version
-
- Version cupsStatusaffectedConstraints<=2.3.3op2-2.1
- Version
-
- Version cupsStatusaffectedConstraints<2.2.7
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| SUSE | SUSE Linux Enterprise Server 11-SP4-LTSS | n/a |
| ||||||
| SUSE | SUSE Manager Server 4.0 | n/a |
| ||||||
| SUSE | SUSE OpenStack Cloud Crowbar 9 | n/a |
| ||||||
| openSUSE | Factory | n/a |
| ||||||
| openSUSE | openSUSE Leap 15.2 | n/a |
|
Configuration 1
Running on/with
- 11
Configuration 2
- 32
- 33
- 34
Configuration 3
Running on/with
- 4.0
Configuration 4
Running on/with
- 9.0
No data.
Red Hat Enterprise Linux 6
cups
Out of support scope
Red Hat Enterprise Linux 7
cups
Fix deferred
Red Hat Enterprise Linux 8
cups
Fix deferred
Red Hat Enterprise Linux 9
cups
Fix deferred
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | cups | Out of support scope | n/a |
| Red Hat Enterprise Linux 7 | cups | Fix deferred | n/a |
| Red Hat Enterprise Linux 8 | cups | Fix deferred | n/a |
| Red Hat Enterprise Linux 9 | cups | Fix deferred | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect the upstream CUPS, only the CUPS versions as packaged by some OS vendors.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
1 other source (Red Hat) ▾
CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:N/I:L/A:N
No CVSS v3.0 score for this CVE.
AV:L/AC:L/Au:N/C:N/I:P/A:N
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2021–2026- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Percentile over time
- EPSS v1
- EPSS v5
- EPSS v2
- EPSS v3
- EPSS v4
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.27% (0.00268) | 17.15th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.27% (0.00268) | 18.17th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.03% (0.00034) | 6.55th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 5.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 5.63th | v3 (v2023.03.01) |
| Mar 6, 2023 | 0.95% (0.00950) | 32.28th | v2 (v2022.01.01) |
| Apr 1, 2022 | 0.95% (0.00950) | 28.61th | v2 (v2022.01.01) |
| Jan 6, 2022 | 2.44% (0.02442) | 53.53th | v1 |
| Jan 5, 2022 | 0.56% (0.00555) | 33.78th | v5 (v2026.06.15) |
| May 5, 2021 | 0.22% (0.00221) | 0.00th | v1 |
References (8)
- https://access.redhat.com/security/cve/CVE-2021-25317 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1949119 Issue Tracking
- https://bugzilla.suse.com/show_bug.cgi?id=1184161 Issue TrackingVendor Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/GWPGZLT3U776Q5YPPSA6LGFWWBDWBVH3/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/H74BP746O5NNVCBUTLLZYAFBPESFVECV/ vendor-advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/S37IDQGHTORQ3Z6VRDQIGBYVOI27YG47/ vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-25317
- https://www.cve.org/CVERecord?id=CVE-2021-25317
Change history (0)
No recorded changes yet.