Impact
A flaw in HP Linux Imaging and Printing Software (HPLIP) causes an integer overflow in the hpcups processing path when it receives specially crafted print data. The overflow allows an attacker to gain elevated privileges or execute arbitrary code on the host, giving full control of the system. Classified as CWE-190, the bug is an incomplete fix to an earlier CVE. The flaw remains in any HPLIP installation that still carries the vulnerable code. Because the problem originates in HPLIP’s printing subsystem, the attack path requires the ability to send a print job to the spooler, which is typical for network‑connected printers.
Affected Systems
Red Hat Enterprise Linux releases 6, 7, 8, 9, 10 ship the vulnerable version of HPLIP. Any system running RHEL that has the hplip package installed and that exposes the CUPS print service to an untrusted network is affected. Systems that do not run the RHEL distribution or that do not are not impacted unless they ship the same vulnerable version.
Risk and Exploitability
The CVSS score of 9.8 classifies the flaw as critical, while an EPSS score of <1% indicates that exploitation is currently rare. The vulnerability is not currently listed in CISA’s KEV catalog. A remote attacker can exploit the flaw by sending a crafted print job over the network are required. A successful compromise results in root privileges, giving an attacker the ability to run arbitrary code, pivot to other systems, or use the host as a command and control platform. The attack vector is network‑based and relies only on access to the printing service.
OpenCVE Enrichment