ZeroHour

CVE-2026-91098

mass

Heap Buffer Overflow in HP Linux Imaging and Printing (HPLIP)

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

CVE-2026-91098 is a heap-based buffer overflow (CWE-122) in HP's Linux Imaging and Printing software (HPLIP), one of multiple externally reported flaws HP says affect several HPLIP software components. Per the CVSS 4.0 vector, it is reachable over the network without privileges but requires user interaction, and under certain conditions can enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification, with high impact on confidentiality, integrity, and availability. Anyone running HPLIP — the standard HP print/scan driver stack on Linux desktops and workstations — is potentially affected. HP has remediated the issues in updated HPLIP releases, but there is no indication of exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's KEV catalog.

What to do: Upgrade HPLIP to the fixed release referenced in HP's security advisory, or apply the patched package via your Linux distribution's update channel as soon as it is backported. Restrict network access to printing services (e.g., CUPS and HPLIP-related daemons) and avoid processing untrusted print or scan jobs until patched; verify the installed HPLIP version with your package manager.

Affected
HPLIP (HP Linux Imaging and Printing)
Estimated exposure
masstens of millions of Linux installations (HPLIP ships by default in major distributions such as Ubuntu, Debian, and Fedora) — HPLIP is the default HP printing/scanning stack bundled with nearly all mainstream Linux distributions, so the pool of installed systems plausibly spans the tens of millions of desktop Linux users, though only those with HP devices or…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

Weakness
CWE-122
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.