Описание
A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.
Отчет
This is an Important security flaw in the HPLIP hpcups component, where HPLIP is vulnerable to integer overflow when processing crafted print data. A remote attacker who can submit print job content to the hpcups filter path may achieve arbitrary code execution or privilege escalation within user used for starting filters (user 'lp' by default) on systems using HPLIP for printing.
Меры по смягчению последствий
To mitigate this vulnerability, consider restricting access to the printing services to trusted users and networks. If HPLIP is not required, removing the hplip package can eliminate the exposure. Note that removing hplip may affect printing functionality.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | hplip | Not affected | ||
| Red Hat Enterprise Linux 7 | hplip | Not affected | ||
| Red Hat Enterprise Linux 10 | hplip | Fixed | RHSA-2026:39976 | 15.07.2026 |
| Red Hat Enterprise Linux 8 | hplip | Fixed | RHSA-2026:40894 | 16.07.2026 |
| Red Hat Enterprise Linux 9 | hplip | Fixed | RHSA-2026:40831 | 16.07.2026 |
Показывать по
Дополнительная информация
Статус:
EPSS
9.8 Critical
CVSS3
Связанные уязвимости
A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.
A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.
A flaw was found in HPLIP (HP Linux Imaging and Printing Software). Th ...
EPSS
9.8 Critical
CVSS3