ZeroHour

CVE-2026-91097

mass

Out-of-bounds write flaws in HP Linux Imaging and Printing (HPLIP)

CVSS 4.0
7.0 high
EPSS
Published
()
Modified
AI analysis

HP has disclosed a set of externally reported vulnerabilities in HPLIP, its Linux imaging and printing driver suite, including at least one out-of-bounds write (CWE-787). Under certain conditions, the affected HPLIP components can enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification. The CVSS 4.0 vector indicates network-based exploitation with no privileges required but user interaction needed, with high integrity impact — consistent with a crafted file, print, or scan job being processed by an affected component. Anyone running HPLIP on Linux (it ships in the repositories of all major distributions to support HP printers and scanners) is potentially affected. No public proof-of-concept, CISA KEV listing, or confirmed exploitation is known at this time.

What to do: Update HPLIP to the latest release from HP or install your distribution's patched package, and verify the installed version with your package manager or hp-check. Since user interaction is required for exploitation, avoid processing untrusted print jobs, scan inputs, or files on Linux hosts running HPLIP. Inventory Linux endpoints with HPLIP installed and prioritize systems where untrusted users can submit print or scan jobs.

Affected
HPLIP (HP Linux Imaging and Printing)
Estimated exposure
massmillions of Linux installations include HPLIP, though only a subset is remotely reachable — HPLIP is the standard HP print/scan driver bundled in the repositories of all major Linux distributions (Ubuntu, Debian, Fedora, openSUSE) and has a multi-decade installed base plausibly in the millions of machines; however, exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

Weakness
CWE-787
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.