CVE-2026-91098
massHeap Buffer Overflow in HP Linux Imaging and Printing (HPLIP)
CVE-2026-91098 is a heap-based buffer overflow (CWE-122) in HP's Linux Imaging and Printing software (HPLIP), one of multiple externally reported flaws HP says affect several HPLIP software components. Per the CVSS 4.0 vector, it is reachable over the network without privileges but requires user interaction, and under certain conditions can enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification, with high impact on confidentiality, integrity, and availability. Anyone running HPLIP — the standard HP print/scan driver stack on Linux desktops and workstations — is potentially affected. HP has remediated the issues in updated HPLIP releases, but there is no indication of exploitation in the wild, no public proof-of-concept, and the flaw is not in CISA's KEV catalog.
What to do: Upgrade HPLIP to the fixed release referenced in HP's security advisory, or apply the patched package via your Linux distribution's update channel as soon as it is backported. Restrict network access to printing services (e.g., CUPS and HPLIP-related daemons) and avoid processing untrusted print or scan jobs until patched; verify the installed HPLIP version with your package manager.
| HPLIP (HP Linux Imaging and Printing) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
- Weakness
- CWE-122
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.