Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14544

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 9.8
EPSS Низкий

Описание

A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.

Отчет

This is an Important security flaw in the HPLIP hpcups component, where HPLIP is vulnerable to integer overflow when processing crafted print data. A remote attacker who can submit print job content to the hpcups filter path may achieve arbitrary code execution or privilege escalation within user used for starting filters (user 'lp' by default) on systems using HPLIP for printing.

Меры по смягчению последствий

To mitigate this vulnerability, consider restricting access to the printing services to trusted users and networks. If HPLIP is not required, removing the hplip package can eliminate the exposure. Note that removing hplip may affect printing functionality.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6hplipNot affected
Red Hat Enterprise Linux 7hplipNot affected
Red Hat Enterprise Linux 10hplipFixedRHSA-2026:3997615.07.2026
Red Hat Enterprise Linux 8hplipFixedRHSA-2026:4089416.07.2026
Red Hat Enterprise Linux 9hplipFixedRHSA-2026:4083116.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2496772HPLIP: Incomplete Fix for CVE-2026-8631

EPSS

Процентиль: 40%
0.00511
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
28 дней назад

A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.

CVSS3: 9.8
nvd
28 дней назад

A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.

CVSS3: 9.8
debian
28 дней назад

A flaw was found in HPLIP (HP Linux Imaging and Printing Software). Th ...

rocky
14 дней назад

Important: hplip security update

rocky
14 дней назад

Important: hplip security update

EPSS

Процентиль: 40%
0.00511
Низкий

9.8 Critical

CVSS3

Уязвимость CVE-2026-14544