Junglewise Threat Intelligence

CVE-2026-14544: HP HPLIP integer overflow in hpcups processing path

CVE-2026-14544 · Severity: critical · CVSS 9.8 · Published 2026-07-03

Technologies: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 8, HPLIP, Red Hat Enterprise Linux 9. Vendors: Hp, Red Hat.

Executive brief

A vulnerability has been identified in the HP Linux Imaging and Printing (HPLIP) software, which is used to manage printing and scanning on Linux systems. An attacker could exploit this flaw by sending specially crafted print data to a system, potentially allowing them to take full control of the computer or gain elevated administrative privileges. This issue is particularly significant as it represents an incomplete fix for a previously reported security flaw, leaving systems vulnerable to unauthorized access and data compromise.

Technical details

A vulnerability classified as an integer overflow (CWE-190) exists within the hpcups processing path of the HP Linux Imaging and Printing (HPLIP) software. This flaw is an incomplete fix for a previous vulnerability (CVE-2026-8631). A remote, unauthenticated attacker can exploit this by submitting specially crafted print data to the affected system. Successful exploitation can lead to arbitrary code execution or local privilege escalation. The vulnerability affects multiple versions of Red Hat Enterprise Linux (8, 9, and 10) where HPLIP is deployed. Users are advised to monitor vendor advisories for updated packages.

Affected products

  • HP HPLIP (HP Linux Imaging and Printing Software) All versions prior to the fix for CVE-2026-14544
  • Red Hat Red Hat Enterprise Linux 8 affected
  • Red Hat Red Hat Enterprise Linux 9 affected
  • Red Hat Red Hat Enterprise Linux 10 affected

Timeline

  • 2026-07-03: disclosed: Vulnerability reported and published to NVD

References

Related threats