CVE-2026-91105
massHeap Buffer Overflow (CWE-122) in HP Linux Imaging and Printing (HPLIP)
HP has remediated a set of externally reported vulnerabilities in HPLIP (HP Linux Imaging and Printing), the standard driver and utility stack for HP printers and scanners on Linux; the flaw tracked here is a heap-based buffer overflow (CWE-122). Per the CVSS 4.0 vector, it is reachable over a network with low complexity and no privileges, but requires user interaction, meaning a victim must perform an action such as handling attacker-crafted content or files processed by HPLIP components. A successful attacker could gain remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification, with high impact to confidentiality, integrity, and availability of the affected machine. Any Linux desktop, workstation, or server running a vulnerable HPLIP installation, including copies bundled with major distributions, is potentially affected. There is currently no evidence of exploitation in the wild, no CISA KEV listing, and no public proof-of-concept.
What to do: Update HPLIP to the latest patched release from HP or install your Linux distribution's HPLIP security update, then confirm the running version with your package manager. Until patched, avoid opening untrusted print/scan-related files and only install HP plugin packages from HP's official servers (e.g., via hp-plugin). On servers, check whether HPLIP is installed and remove it where printing/scanning is not needed to shrink attack surface.
| HPLIP (HP Linux Imaging and Printing) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.
- Weakness
- CWE-122
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.