The Network Printing Vulnerability
In Ubuntu and many other Linux distributions, the Common UNIX Printing System (CUPS) is used to manage local and network printers. A specific component of this system, known as the cups-browsed daemon, is responsible for automatically discovering network printers via protocols like Bonjour and SNMP. While this is highly convenient on a trusted home or corporate network, running this daemon continuously on a public Wi-Fi network or an internet-facing server exposes your machine to potential remote code execution vulnerabilities, as it constantly listens for unauthenticated network broadcasting packets.
Securing the Print Service
If you do not regularly print to network-discovered printers, or if you prefer to manually configure your printer IP addresses, you should disable the daemon entirely to harden your system’s security posture. Open your terminal window (Ctrl+Alt+T) to execute the system management commands.
First, immediately stop the running service by typing sudo systemctl stop cups-browsed and pressing Enter. Next, to ensure the daemon does not automatically restart the next time you boot your computer, disable the service entirely by running sudo systemctl disable cups-browsed. Finally, for absolute security on internet-facing servers, you can mask the service to prevent any other software from accidentally waking it up by typing sudo systemctl mask cups-browsed. Your system will no longer scan the network for rogue printing devices.