CRITICAL🇵🇱 Wersja polska

CVE-2026-8631

CVSS 9.3v4.0pub. 2026-05-20upd. 2026-08-04

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.

🤖 AI Analysis
How it works

The vulnerability results from an integer overflow error (CWE-190) in the hpcups component responsible for processing print data, leading to heap-based buffer overflow (CWE-122). An attacker can send specially crafted print data that triggers incorrect buffer size calculations, resulting in out-of-bounds write. The attack vector is network-based, requires no authentication or user interaction, significantly increasing the risk of vulnerability exploitation.

Impact

Successful exploitation of the vulnerability may allow an attacker to escalate privileges on the system and execute arbitrary code (RCE) in the context of the printing service process.

Mitigation & patch

Patches available from the vendor should be applied in accordance with the references (HP security bulletin HPSBPI04118). It is recommended to monitor the official HP support channel at https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118 to obtain updated versions of HPLIP software.

Who is affected

HP Linux Imaging and Printing Software (HPLIP) — specific versions indicated in vendor references (https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • HP Linux Imaging And Printing

    APP
    Hp
    < 3.26.4
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-8632HIGH8.5same product

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This pot...

CVE-2015-0839HIGH8.1same product

The hp-plugin utility in HP Linux Imaging and Printing (HPLIP) makes it easier for man-in-the-middle attackers...

CVE-2025-43023MEDIUM5.9same product

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software documenta...

CVE-2017-5638CRITICAL9.8⚠ KEVPL ✓same vendor

RCE w Apache Struts 2 poprzez błędną obsługę nagłówków HTTP (Jakarta Multipart parser)

CVE-2015-3113CRITICAL9.8⚠ KEVPL ✓same vendor

RCE w Adobe Flash Player — heap-based buffer overflow (CVE-2015-3113)