CVE-2026-8631 (original) (raw)

Name CVE-2026-8631
Description A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.
Source CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs 1137374

Vulnerable and fixed packages

The table below lists information on source packages.

Source Package Release Version Status
hplip (PTS) bullseye 3.21.2+dfsg1-2 vulnerable
bookworm 3.22.10+dfsg0-2 vulnerable
trixie 3.22.10+dfsg0-8.1 vulnerable
sid, forky 3.26.4+dfsg0-2 fixed

The information below is based on the following data on fixed versions.

Package Type Release Fixed Version Urgency Origin Debian Bugs
hplip source (unstable) 3.26.4+dfsg0-1 1137374

Notes

https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118