ZeroHour

CVE-2026-91104

mass

Heap-based Buffer Overflow in HP Linux Imaging and Printing (HPLIP)

CVSS 4.0
9.3 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-91104 is a heap-based buffer overflow (CWE-122) in HP's Linux Imaging and Printing (HPLIP) software, the driver and utility stack used to run HP printers and scanners on Linux; it was remediated by HP alongside several other externally reported HPLIP flaws that could allow remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. The CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N with high confidentiality, integrity, and availability impact) indicates it can be triggered remotely over a network without privileges or user interaction. A successful attacker could potentially execute arbitrary code in the context of the affected HPLIP component. Anyone running HPLIP on Linux desktops, workstations, or servers with HP printing or scanning support is potentially affected, including systems where it is installed by default with the distribution. No public proof of concept, CISA KEV listing, or confirmed exploitation is known at this time.

What to do: Update HPLIP to the latest patched release via your distribution's package manager (e.g., apt/dnf security updates) or HP's official HPLIP download page, since the advisory does not name a specific fixed version. Check whether HPLIP is installed (`dpkg -l | grep hplip` or equivalent) and restrict network access to print services such as CUPS and HPLIP daemons to trusted hosts as a mitigation.

Affected
HPLIP (HP Linux Imaging and Printing)
Estimated exposure
mass≈1,000,000+ installations (HPLIP ships by default or as the standard HP driver in major Linux distributions) — HPLIP is the default HP printing/scanning stack bundled in Ubuntu, Debian, Fedora, and other major Linux distributions with tens of millions of combined users, so the global install base plausibly exceeds one million, though only a subset…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

Weakness
CWE-122
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.