Description
A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.
Published: 2026-07-03
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in HP Linux Imaging and Printing Software (HPLIP) causes an integer overflow in the hpcups processing path when it receives specially crafted print data. The overflow allows an attacker to gain elevated privileges or execute arbitrary code on the host, giving full control of the system. Classified as CWE-190, the bug is an incomplete fix to an earlier CVE. The flaw remains in any HPLIP installation that still carries the vulnerable code. Because the problem originates in HPLIP’s printing subsystem, the attack path requires the ability to send a print job to the spooler, which is typical for network‑connected printers.

Affected Systems

Red Hat Enterprise Linux releases 6, 7, 8, 9, 10 ship the vulnerable version of HPLIP. Any system running RHEL that has the hplip package installed and that exposes the CUPS print service to an untrusted network is affected. Systems that do not run the RHEL distribution or that do not are not impacted unless they ship the same vulnerable version.

Risk and Exploitability

The CVSS score of 9.8 classifies the flaw as critical, while an EPSS score of <1% indicates that exploitation is currently rare. The vulnerability is not currently listed in CISA’s KEV catalog. A remote attacker can exploit the flaw by sending a crafted print job over the network are required. A successful compromise results in root privileges, giving an attacker the ability to run arbitrary code, pivot to other systems, or use the host as a command and control platform. The attack vector is network‑based and relies only on access to the printing service.

Generated by OpenCVE AI on July 21, 2026 at 10:08 UTC.

Remediation

Vendor Workaround

To mitigate this vulnerability, consider restricting access to the printing services to trusted users and networks. If HPLIP is not required, removing the `hplip` package can eliminate the exposure. Note that removing `hplip` may affect printing functionality.


OpenCVE Recommended Actions

  • Uninstall the hplip package to remove the vulnerability entirely.
  • Restrict the print spooler’s network access to trusted hosts only, by binding services to the loopback interface, requiring authentication, or using ACLs and firewall rules.
  • Segment the network or apply firewall rules to block remote access to the spooler unless explicitly required.
  • Monitor system logs for hpcups events or errors, and keep HPL as patches are released.

Generated by OpenCVE AI on July 21, 2026 at 10:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:8 cpe:/a:redhat:enterprise_linux:8::appstream
References

Thu, 16 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:9 cpe:/a:redhat:enterprise_linux:9::appstream
References

Wed, 15 Jul 2026 20:45:00 +0000

Type Values Removed Values Added
CPEs cpe:/o:redhat:enterprise_linux:10 cpe:/o:redhat:enterprise_linux:10.2
References

Mon, 06 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 03 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Fri, 03 Jul 2026 08:00:00 +0000

Type Values Removed Values Added
Description A flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.
Title Hplip: incomplete fix for cve-2026-8631
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-190
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-16T11:47:51.901Z

Reserved: 2026-07-03T07:06:13.196Z

Link: CVE-2026-14544

cve-icon Vulnrichment

Updated: 2026-07-06T14:14:45.472Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-03T00:00:00Z

Links: CVE-2026-14544 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:15:02Z

Weaknesses
  • CWE-190

    Integer Overflow or Wraparound