A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing a printer-advertised IEEE-1284 device ID with an empty model field, causing sustained CPU consumption. A network-adjacent attacker could exploit this by broadcasting a specially crafted printer advertisement, leading to denial of service.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-64611 exploits a flaw in libcupsfilters where the cfIEEE1284NormalizeMakeModel() function enters an infinite loop when processing printer advertisements containing an empty model field in the IEEE-1284 device ID string. This vulnerability enables network-adjacent attackers to trigger sustained CPU consumption through specially crafted printer broadcasts, resulting in denial of service. The impact is particularly significant for organizations managing networked printing infrastructure, including enterprises, educational institutions, and service providers that rely on CUPS (Common Unix Printing System) for printer management. Systems running vulnerable versions of libcupsfilters become susceptible to resource exhaustion attacks that require minimal attacker sophistication and can be executed from any network position adjacent to the target environment.
While this CVE currently maps to zero Casky skills due to its focus on a specific library function vulnerability rather than established ATT&CK techniques, Casky's Claude-powered analysis would detect the underlying attack pattern through resource consumption anomalies and network printer enumeration activities. Practitioners would identify suspicious indicators including: abnormal CPU spikes correlating with printer discovery traffic, repeated IEEE-1284 device ID queries from unknown network sources, and printer advertisement packets with malformed or empty model fields in CUPS logs. Extended reasoning would recognize this as an indirect Denial of Service attack (ATT&CK T1499) achieved through resource exhaustion, with detection logic focusing on sustained CPU utilization patterns, network printer reconnaissance, and anomalous CUPS service behavior—allowing teams to isolate affected systems and implement network segmentation around printer infrastructure before exploitation occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-64611. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation