CVE-2026-14544

NameCVE-2026-14544
DescriptionA flaw was found in HPLIP (HP Linux Imaging and Printing Software). This vulnerability, an incomplete fix for CVE-2026-8631, may allow a remote attacker to escalate privileges or achieve arbitrary code execution. This can occur through an integer overflow in the hpcups processing path when handling specially crafted print data.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
hplip (PTS)bullseye3.21.2+dfsg1-2fixed
bullseye (security)3.21.2+dfsg1-2+deb11u1fixed
bookworm3.22.10+dfsg0-2fixed
bookworm (security)3.22.10+dfsg0-2+deb12u1fixed
trixie3.22.10+dfsg0-8.1fixed
trixie (security)3.22.10+dfsg0-8.1+deb13u1fixed
forky, sid3.26.4+dfsg0-3fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
hplipsource(unstable)(not affected)

Notes

- hplip <not-affected> (Red Hat specific incomplete fix for CVE-2026-8631 backport)
https://bugzilla.redhat.com/show_bug.cgi?id=2496772

Search for package or bug name: Reporting problems