CVE-2026-8631
critical
CVSS v3
9.8
CVSS v2
—
VIR risk
9.8
Description
A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution via an integer overflow in the hpcups processing path when handling crafted print data.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2026-8631.html
Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2026-8631
Vendor advisory: hp-security-alert@hp.com — https://support.hp.com/us-en/document/ish_14942099-14942126-16/hpsbpi04118
OS impact
| OS | Version | Status | Fixed in |
|---|---|---|---|
| debian | bookworm | affected | |
| debian | bullseye | affected | |
| debian | sid | fixed | 3.26.4+dfsg0-1 |
| debian | trixie | affected | |
| sles | affected | |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| hp | linux_imaging_and_printing | {"endExcluding":"3.26.4"} | 3.26.4 |
References
CWEs
CWE-122 CWE-190
Verify integrity in audit chain (admin only). AS-IS.