CVE-2026-91104
massHeap-based Buffer Overflow in HP Linux Imaging and Printing (HPLIP)
CVE-2026-91104 is a heap-based buffer overflow (CWE-122) in HP's Linux Imaging and Printing (HPLIP) software, the driver and utility stack used to run HP printers and scanners on Linux; it was remediated by HP alongside several other externally reported HPLIP flaws that could allow remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. The CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:N with high confidentiality, integrity, and availability impact) indicates it can be triggered remotely over a network without privileges or user interaction. A successful attacker could potentially execute arbitrary code in the context of the affected HPLIP component. Anyone running HPLIP on Linux desktops, workstations, or servers with HP printing or scanning support is potentially affected, including systems where it is installed by default with the distribution. No public proof of concept, CISA KEV listing, or confirmed exploitation is known at this time.
What to do: Update HPLIP to the latest patched release via your distribution's package manager (e.g., apt/dnf security updates) or HP's official HPLIP download page, since the advisory does not name a specific fixed version. Check whether HPLIP is installed (`dpkg -l | grep hplip` or equivalent) and restrict network access to print services such as CUPS and HPLIP daemons to trusted hosts as a mitigation.
| HPLIP (HP Linux Imaging and Printing) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
- Weakness
- CWE-122
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.