ZeroHour

CVE-2026-91106

mass

Heap-Based Buffer Overflow in HP Linux Imaging and Printing (HPLIP)

CVSS 4.0
9.3 critical
EPSS
Published
()
Modified
AI analysis

HP has disclosed a critical vulnerability (CWE-122, heap-based buffer overflow) in HPLIP (HP Linux Imaging and Printing), part of a batch of externally reported flaws in several HPLIP components. According to the CVSS 4.0 vector, it can be triggered remotely over a network with low attack complexity, no privileges required, and no user interaction, and could enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions. Anyone running HPLIP to drive HP printers or scanners on Linux is potentially affected, with the greatest risk on systems where HPLIP-related services are reachable from the network. As of now there is no evidence of exploitation, no public proof of concept, and the flaw is not in CISA's Known Exploited Vulnerabilities catalog. HP has released remediation, so users should move to the patched HPLIP release.

What to do: Update HPLIP to the latest patched release from HP or apply the HPLIP security update provided through your Linux distribution's package manager. Audit systems for HPLIP/hp-* services exposed to untrusted networks and restrict access where possible. Monitor HP's security advisory for the specific fixed version and component details.

Affected
HPLIP (HP Linux Imaging and Printing)Multiple versions prior to the patched release; HP's advisory lists several affected software components but does not specify exact version ranges in this data
Estimated exposure
massOn the order of millions of Linux desktops and servers running HPLIP (bundled by major distributions), though only a subset are remotely reachable — HPLIP is the default HP printing/scanning stack shipped in mainstream Linux distributions (Ubuntu, Debian, Fedora, openSUSE, etc.), and HP is one of the largest printer vendors, so the installed base plausibly exceeds one million systems;…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

HP has identified and remediated multiple externally reported vulnerabilities within HPLIP. The findings affect several software components that could potentially enable remote code execution, privilege escalation, denial of service, information disclosure, or unauthorized file modification under certain conditions.

Weakness
CWE-122
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.