CVE-2026-8631 hplip: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups
Resolves: RHEL-178728
This commit is contained in:
parent
574e6df98e
commit
4045b63ef3
92
hplip-CVE-2026-8631-osh.patch
Normal file
92
hplip-CVE-2026-8631-osh.patch
Normal file
@ -0,0 +1,92 @@
|
||||
diff -up hplip-3.21.2/prnt/hpcups/genPCLm.cpp.CVE-2026-8631-osh hplip-3.21.2/prnt/hpcups/genPCLm.cpp
|
||||
--- hplip-3.21.2/prnt/hpcups/genPCLm.cpp.CVE-2026-8631-osh 2026-07-03 08:25:17.717888763 +0200
|
||||
+++ hplip-3.21.2/prnt/hpcups/genPCLm.cpp 2026-07-03 08:48:22.225130940 +0200
|
||||
@@ -1922,7 +1922,10 @@ int PCLmGenerator::Encapsulate(void *pI
|
||||
int whiteStripLen=0;
|
||||
if(!safe_mul_int_positive(thisHeight, currSourceWidth, &whiteStripLen) ||
|
||||
!safe_mul_int_positive(whiteStripLen, srcNumComponents, &whiteStripLen))
|
||||
+ {
|
||||
+ free(newStripPtr);
|
||||
return(errorOutAndCleanUp());
|
||||
+ }
|
||||
bool whiteStrip=isWhiteStrip(pInBuffer, whiteStripLen);
|
||||
if(DebugIt2)
|
||||
{
|
||||
@@ -1944,11 +1947,17 @@ int PCLmGenerator::Encapsulate(void *pI
|
||||
ubyte whitePt=0xff;
|
||||
size_t tmpStripSize=0;
|
||||
if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize))
|
||||
+ {
|
||||
+ free(newStripPtr);
|
||||
return(errorOutAndCleanUp());
|
||||
+ }
|
||||
|
||||
ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize);
|
||||
if(!tmpStrip)
|
||||
+ {
|
||||
+ free(newStripPtr);
|
||||
return(errorOutAndCleanUp());
|
||||
+ }
|
||||
memset(tmpStrip,whitePt,tmpStripSize);
|
||||
|
||||
|
||||
@@ -2016,7 +2025,10 @@ int PCLmGenerator::Encapsulate(void *pI
|
||||
{
|
||||
int sourceLen=0;
|
||||
if(!safe_mul_int_positive(numLinesThisCall, scanlineWidth, &sourceLen))
|
||||
+ {
|
||||
+ free(newStripPtr);
|
||||
return(errorOutAndCleanUp());
|
||||
+ }
|
||||
uint32 len=(uint32)sourceLen;
|
||||
uLongf destSize=len;
|
||||
|
||||
@@ -2025,12 +2037,18 @@ int PCLmGenerator::Encapsulate(void *pI
|
||||
ubyte whitePt=0xff;
|
||||
size_t tmpStripSize=0;
|
||||
if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize))
|
||||
+ {
|
||||
+ free(newStripPtr);
|
||||
return(errorOutAndCleanUp());
|
||||
+ }
|
||||
|
||||
// We need to inject a blank image-strip with a height==topMarginInPix
|
||||
ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize);
|
||||
if(!tmpStrip)
|
||||
+ {
|
||||
+ free(newStripPtr);
|
||||
return(errorOutAndCleanUp());
|
||||
+ }
|
||||
uLongf tmpDestSize=destSize;
|
||||
memset(tmpStrip,whitePt,tmpStripSize);
|
||||
|
||||
@@ -2079,20 +2097,29 @@ int PCLmGenerator::Encapsulate(void *pI
|
||||
{
|
||||
int sourceLen=0;
|
||||
if(!safe_mul_int_positive(numLinesThisCall, scanlineWidth, &sourceLen))
|
||||
+ {
|
||||
+ free(newStripPtr);
|
||||
return(errorOutAndCleanUp());
|
||||
+ }
|
||||
|
||||
if(firstStrip && topMarginInPix)
|
||||
{
|
||||
ubyte whitePt=0xff;
|
||||
size_t tmpStripSize=0;
|
||||
if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize))
|
||||
+ {
|
||||
+ free(newStripPtr);
|
||||
return(errorOutAndCleanUp());
|
||||
+ }
|
||||
|
||||
// We need to inject a blank image-strip with a height==topMarginInPix
|
||||
|
||||
ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize);
|
||||
if(!tmpStrip)
|
||||
+ {
|
||||
+ free(newStripPtr);
|
||||
return(errorOutAndCleanUp());
|
||||
+ }
|
||||
memset(tmpStrip,whitePt,tmpStripSize);
|
||||
|
||||
for(sint32 stripCntr=0; stripCntr<numFullInjectedStrips;stripCntr++)
|
||||
495
hplip-CVE-2026-8631.patch
Normal file
495
hplip-CVE-2026-8631.patch
Normal file
@ -0,0 +1,495 @@
|
||||
diff -up hplip-3.21.2/common/utils.h.CVE-2026-8631 hplip-3.21.2/common/utils.h
|
||||
--- hplip-3.21.2/common/utils.h.CVE-2026-8631 2021-02-15 00:55:21.000000000 +0100
|
||||
+++ hplip-3.21.2/common/utils.h 2026-06-10 10:43:30.497271871 +0200
|
||||
@@ -4,6 +4,10 @@
|
||||
#include <stdio.h>
|
||||
#include <stdarg.h>
|
||||
#include <syslog.h>
|
||||
+#include <stdint.h>
|
||||
+#include <limits.h>
|
||||
+#include <stdbool.h>
|
||||
+#include <stddef.h>
|
||||
//#include "hpmud.h"
|
||||
|
||||
#define _STRINGIZE(x) #x
|
||||
@@ -54,6 +58,52 @@ enum UTILS_PLUGIN_LIBRARY_TYPE
|
||||
};
|
||||
|
||||
|
||||
+/* Safe multiplication helpers - prevent integer overflow */
|
||||
+
|
||||
+/**
|
||||
+ * safe_mul_size_t - Safely multiply two size_t values
|
||||
+ * @a: First operand
|
||||
+ * @b: Second operand
|
||||
+ * @out: Output buffer for result
|
||||
+ * Returns: true if multiplication succeeded, false if overflow detected
|
||||
+ */
|
||||
+static inline bool safe_mul_size_t(size_t a, size_t b, size_t *out)
|
||||
+{
|
||||
+ if (!out)
|
||||
+ return false;
|
||||
+ if (a == 0 || b == 0)
|
||||
+ {
|
||||
+ *out = 0;
|
||||
+ return true;
|
||||
+ }
|
||||
+ if (a > ((size_t)-1) / b)
|
||||
+ return false;
|
||||
+ *out = a * b;
|
||||
+ return true;
|
||||
+}
|
||||
+
|
||||
+/**
|
||||
+ * safe_mul_int_positive - Safely multiply two positive integers
|
||||
+ * @a: First operand (must be >= 0)
|
||||
+ * @b: Second operand (must be >= 0)
|
||||
+ * @out: Output buffer for result
|
||||
+ * Returns: true if multiplication succeeded, false if negative input or overflow detected
|
||||
+ */
|
||||
+static inline bool safe_mul_int_positive(int a, int b, int *out)
|
||||
+{
|
||||
+ if (!out || a < 0 || b < 0)
|
||||
+ return false;
|
||||
+ if (a == 0 || b == 0)
|
||||
+ {
|
||||
+ *out = 0;
|
||||
+ return true;
|
||||
+ }
|
||||
+ if (a > INT_MAX / b)
|
||||
+ return false;
|
||||
+ *out = a * b;
|
||||
+ return true;
|
||||
+}
|
||||
+
|
||||
#ifdef __cplusplus
|
||||
extern "C" {
|
||||
#endif
|
||||
diff -up hplip-3.21.2/prnt/hpcups/genPCLm.cpp.CVE-2026-8631 hplip-3.21.2/prnt/hpcups/genPCLm.cpp
|
||||
--- hplip-3.21.2/prnt/hpcups/genPCLm.cpp.CVE-2026-8631 2026-06-10 10:43:30.459529186 +0200
|
||||
+++ hplip-3.21.2/prnt/hpcups/genPCLm.cpp 2026-06-10 10:43:30.497932359 +0200
|
||||
@@ -127,6 +127,7 @@
|
||||
#include <fcntl.h>
|
||||
#include <assert.h>
|
||||
#include <math.h>
|
||||
+#include <limits.h>
|
||||
#include <zlib.h>
|
||||
//#include <unistd.h>
|
||||
|
||||
@@ -1674,7 +1675,12 @@ int PCLmGenerator::StartPage(PCLmPageSe
|
||||
destColorSpace=PCLmPageContent->dstColorSpaceSpefication;
|
||||
|
||||
// Calculate how large the output buffer needs to be based upon the page specifications
|
||||
- int tmp_outBuffSize=mediaWidthInPixels*currStripHeight*dstNumComponents;
|
||||
+ int tmp_outBuffSize=0;
|
||||
+ if(!safe_mul_int_positive(mediaWidthInPixels,currStripHeight,&tmp_outBuffSize) ||
|
||||
+ !safe_mul_int_positive(tmp_outBuffSize,dstNumComponents,&tmp_outBuffSize))
|
||||
+ {
|
||||
+ return(errorOutAndCleanUp());
|
||||
+ }
|
||||
|
||||
if(tmp_outBuffSize>currOutBuffSize)
|
||||
{
|
||||
@@ -1742,7 +1748,14 @@ int PCLmGenerator::StartPage(PCLmPageSe
|
||||
{
|
||||
// We need to pad the scratchBuffer size to allow for compression expansion (RLE can create
|
||||
// compressed segments that are slightly larger than the source.
|
||||
- scratchBuffer=(ubyte*)malloc(currStripHeight*mediaWidthInPixels*srcNumComponents*2);
|
||||
+ size_t scratchSize=0;
|
||||
+ if(currStripHeight<=0 || mediaWidthInPixels<=0 || srcNumComponents<=0 ||
|
||||
+ !safe_mul_size_t((size_t)currStripHeight, (size_t)mediaWidthInPixels, &scratchSize) ||
|
||||
+ !safe_mul_size_t(scratchSize, (size_t)srcNumComponents, &scratchSize) ||
|
||||
+ !safe_mul_size_t(scratchSize, 2u, &scratchSize))
|
||||
+ return(errorOutAndCleanUp());
|
||||
+
|
||||
+ scratchBuffer=(ubyte*)malloc(scratchSize);
|
||||
if(!scratchBuffer)
|
||||
return(errorOutAndCleanUp());
|
||||
/*if(DebugIt2)
|
||||
@@ -1798,7 +1811,9 @@ int PCLmGenerator::SkipLines(int iSkipL
|
||||
int PCLmGenerator::Encapsulate(void *pInBuffer, int inBufferSize, int thisHeight, void **pOutBuffer, int *iOutBufferSize)
|
||||
{
|
||||
int result=0, numCompBytes;
|
||||
- int scanlineWidth=mediaWidthInPixels*srcNumComponents;
|
||||
+ int scanlineWidth=0;
|
||||
+ if(!safe_mul_int_positive(mediaWidthInPixels, srcNumComponents, &scanlineWidth))
|
||||
+ return(errorOutAndCleanUp());
|
||||
int compSize;
|
||||
// int numLinesThisCall=inBufferSize/(currSourceWidth*srcNumComponents);
|
||||
int numLinesThisCall=thisHeight;
|
||||
@@ -1888,7 +1903,8 @@ int PCLmGenerator::Encapsulate(void *pI
|
||||
{
|
||||
colorConvertSource(sourceColorSpace, grayScale, (ubyte*)localInBuffer, currSourceWidth, numLinesThisCall);
|
||||
// Adjust the scanline width accordingly
|
||||
- scanlineWidth = mediaWidthInPixels * dstNumComponents;
|
||||
+ if(!safe_mul_int_positive(mediaWidthInPixels, dstNumComponents, &scanlineWidth))
|
||||
+ return(errorOutAndCleanUp());
|
||||
}
|
||||
|
||||
if(leftMarginInPix)
|
||||
@@ -1903,7 +1919,11 @@ int PCLmGenerator::Encapsulate(void *pI
|
||||
}
|
||||
|
||||
#ifdef SUPPORT_WHITE_STRIPS
|
||||
- bool whiteStrip=isWhiteStrip(pInBuffer, thisHeight*currSourceWidth*srcNumComponents);
|
||||
+ int whiteStripLen=0;
|
||||
+ if(!safe_mul_int_positive(thisHeight, currSourceWidth, &whiteStripLen) ||
|
||||
+ !safe_mul_int_positive(whiteStripLen, srcNumComponents, &whiteStripLen))
|
||||
+ return(errorOutAndCleanUp());
|
||||
+ bool whiteStrip=isWhiteStrip(pInBuffer, whiteStripLen);
|
||||
if(DebugIt2)
|
||||
{
|
||||
if(whiteStrip){
|
||||
@@ -1922,9 +1942,14 @@ int PCLmGenerator::Encapsulate(void *pI
|
||||
if(firstStrip && topMarginInPix)
|
||||
{
|
||||
ubyte whitePt=0xff;
|
||||
-
|
||||
- ubyte *tmpStrip=(ubyte*)malloc(scanlineWidth*topMarginInPix);
|
||||
- memset(tmpStrip,whitePt,scanlineWidth*topMarginInPix);
|
||||
+ size_t tmpStripSize=0;
|
||||
+ if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize))
|
||||
+ return(errorOutAndCleanUp());
|
||||
+
|
||||
+ ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize);
|
||||
+ if(!tmpStrip)
|
||||
+ return(errorOutAndCleanUp());
|
||||
+ memset(tmpStrip,whitePt,tmpStripSize);
|
||||
|
||||
|
||||
for(sint32 stripCntr=0; stripCntr<numFullInjectedStrips;stripCntr++)
|
||||
@@ -1989,17 +2014,25 @@ int PCLmGenerator::Encapsulate(void *pI
|
||||
}
|
||||
else if(currCompressionDisposition==compressFlate)
|
||||
{
|
||||
- uint32 len=numLinesThisCall*scanlineWidth;
|
||||
+ int sourceLen=0;
|
||||
+ if(!safe_mul_int_positive(numLinesThisCall, scanlineWidth, &sourceLen))
|
||||
+ return(errorOutAndCleanUp());
|
||||
+ uint32 len=(uint32)sourceLen;
|
||||
uLongf destSize=len;
|
||||
|
||||
if(firstStrip && topMarginInPix)
|
||||
{
|
||||
ubyte whitePt=0xff;
|
||||
+ size_t tmpStripSize=0;
|
||||
+ if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize))
|
||||
+ return(errorOutAndCleanUp());
|
||||
|
||||
// We need to inject a blank image-strip with a height==topMarginInPix
|
||||
- ubyte *tmpStrip=(ubyte*)malloc(scanlineWidth*topMarginInPix);
|
||||
+ ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize);
|
||||
+ if(!tmpStrip)
|
||||
+ return(errorOutAndCleanUp());
|
||||
uLongf tmpDestSize=destSize;
|
||||
- memset(tmpStrip,whitePt,scanlineWidth*topMarginInPix);
|
||||
+ memset(tmpStrip,whitePt,tmpStripSize);
|
||||
|
||||
for(sint32 stripCntr=0; stripCntr<numFullInjectedStrips;stripCntr++)
|
||||
{
|
||||
@@ -2017,12 +2050,12 @@ int PCLmGenerator::Encapsulate(void *pI
|
||||
|
||||
if(newStripPtr)
|
||||
{
|
||||
- result=compress((Bytef*)scratchBuffer,&destSize,(const Bytef*)newStripPtr,scanlineWidth*numLinesThisCall);
|
||||
+ result=compress((Bytef*)scratchBuffer,&destSize,(const Bytef*)newStripPtr,(uLong)sourceLen);
|
||||
if(DebugIt2)
|
||||
writeOutputFile(destSize, scratchBuffer, m_pPCLmSSettings->user_name);
|
||||
if(DebugIt2)
|
||||
{
|
||||
- dbglog("Allocated zlib dest buffer of size %d\n",numLinesThisCall*scanlineWidth);
|
||||
+ dbglog("Allocated zlib dest buffer of size %d\n",sourceLen);
|
||||
dbglog("zlib compression return result=%d, compSize=%d\n",result,(int)destSize);
|
||||
}
|
||||
free(newStripPtr);
|
||||
@@ -2030,12 +2063,12 @@ int PCLmGenerator::Encapsulate(void *pI
|
||||
}
|
||||
else
|
||||
{
|
||||
- result=compress((Bytef*)scratchBuffer, &destSize, (const Bytef*)localInBuffer, scanlineWidth*numLinesThisCall);
|
||||
+ result=compress((Bytef*)scratchBuffer, &destSize, (const Bytef*)localInBuffer, (uLong)sourceLen);
|
||||
if(DebugIt2)
|
||||
writeOutputFile(destSize, scratchBuffer, m_pPCLmSSettings->user_name);
|
||||
if(DebugIt2)
|
||||
{
|
||||
- dbglog("Allocated zlib dest buffer of size %d\n",numLinesThisCall*scanlineWidth);
|
||||
+ dbglog("Allocated zlib dest buffer of size %d\n",sourceLen);
|
||||
dbglog("zlib compression return result=%d, compSize=%d\n",result,(int)destSize);
|
||||
}
|
||||
}
|
||||
@@ -2044,14 +2077,23 @@ int PCLmGenerator::Encapsulate(void *pI
|
||||
|
||||
else if(currCompressionDisposition==compressRLE)
|
||||
{
|
||||
+ int sourceLen=0;
|
||||
+ if(!safe_mul_int_positive(numLinesThisCall, scanlineWidth, &sourceLen))
|
||||
+ return(errorOutAndCleanUp());
|
||||
+
|
||||
if(firstStrip && topMarginInPix)
|
||||
{
|
||||
ubyte whitePt=0xff;
|
||||
+ size_t tmpStripSize=0;
|
||||
+ if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize))
|
||||
+ return(errorOutAndCleanUp());
|
||||
|
||||
// We need to inject a blank image-strip with a height==topMarginInPix
|
||||
|
||||
- ubyte *tmpStrip=(ubyte*)malloc(scanlineWidth*topMarginInPix);
|
||||
- memset(tmpStrip,whitePt,scanlineWidth*topMarginInPix);
|
||||
+ ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize);
|
||||
+ if(!tmpStrip)
|
||||
+ return(errorOutAndCleanUp());
|
||||
+ memset(tmpStrip,whitePt,tmpStripSize);
|
||||
|
||||
for(sint32 stripCntr=0; stripCntr<numFullInjectedStrips;stripCntr++)
|
||||
{
|
||||
@@ -2071,16 +2113,16 @@ int PCLmGenerator::Encapsulate(void *pI
|
||||
|
||||
if(newStripPtr)
|
||||
{
|
||||
- compSize=HPRunLen_Encode((ubyte*)newStripPtr, scratchBuffer, scanlineWidth*numLinesThisCall);
|
||||
+ compSize=HPRunLen_Encode((ubyte*)newStripPtr, scratchBuffer, sourceLen);
|
||||
free(newStripPtr);
|
||||
newStripPtr = NULL;
|
||||
}
|
||||
else
|
||||
- compSize=HPRunLen_Encode((ubyte*)localInBuffer, scratchBuffer, scanlineWidth*numLinesThisCall);
|
||||
+ compSize=HPRunLen_Encode((ubyte*)localInBuffer, scratchBuffer, sourceLen);
|
||||
|
||||
if(DebugIt2)
|
||||
{
|
||||
- dbglog("Allocated rle dest buffer of size %d\n",numLinesThisCall*scanlineWidth);
|
||||
+ dbglog("Allocated rle dest buffer of size %d\n",sourceLen);
|
||||
dbglog("rle compression return size=%d=%d\n",result,(int)compSize);
|
||||
}
|
||||
injectRLEStrip(scratchBuffer, compSize, mediaWidthInPixels, numLinesThisCall, destColorSpace, whiteStrip);
|
||||
diff -up hplip-3.21.2/prnt/hpcups/Hbpl1.cpp.CVE-2026-8631 hplip-3.21.2/prnt/hpcups/Hbpl1.cpp
|
||||
--- hplip-3.21.2/prnt/hpcups/Hbpl1.cpp.CVE-2026-8631 2021-02-15 00:55:21.000000000 +0100
|
||||
+++ hplip-3.21.2/prnt/hpcups/Hbpl1.cpp 2026-06-10 10:50:47.505618389 +0200
|
||||
@@ -130,8 +130,19 @@ DRIVER_ERROR Hbpl1::StartJob(SystemServi
|
||||
m_PrintinGrayscale = m_JA.integer_values[3]; // cupsInterger3 value
|
||||
m_pSystemServices = pSystemServices; //Reset and UEL not required
|
||||
err = m_pHbpl1Wrapper->StartJob((void**)&m_pOutBuffer, &m_OutBuffSize);
|
||||
- err = sendBuffer(static_cast<const BYTE *>(m_pOutBuffer), m_OutBuffSize);
|
||||
- m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize);
|
||||
+ if (err != NO_ERROR)
|
||||
+ {
|
||||
+ return err;
|
||||
+ }
|
||||
+ if (m_pOutBuffer != NULL && m_OutBuffSize > 0)
|
||||
+ {
|
||||
+ err = sendBuffer(static_cast<const BYTE *>(m_pOutBuffer), m_OutBuffSize);
|
||||
+ m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize);
|
||||
+ if (err != NO_ERROR)
|
||||
+ {
|
||||
+ return err;
|
||||
+ }
|
||||
+ }
|
||||
|
||||
if (m_PrintinGrayscale == ON){ //Grayscale = ON
|
||||
m_ColorMode = COLORTYPE_BOTH;
|
||||
@@ -156,8 +167,15 @@ DRIVER_ERROR Hbpl1::EndJob()
|
||||
}
|
||||
|
||||
err = m_pHbpl1Wrapper->EndJob((void**)&m_pOutBuffer, &m_OutBuffSize);
|
||||
- err = sendBuffer(static_cast<const BYTE *>(m_pOutBuffer), m_OutBuffSize);
|
||||
- m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize);
|
||||
+ if (err != NO_ERROR)
|
||||
+ {
|
||||
+ return err;
|
||||
+ }
|
||||
+ if (m_pOutBuffer != NULL && m_OutBuffSize > 0)
|
||||
+ {
|
||||
+ err = sendBuffer(static_cast<const BYTE *>(m_pOutBuffer), m_OutBuffSize);
|
||||
+ m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize);
|
||||
+ }
|
||||
return err;
|
||||
}
|
||||
|
||||
@@ -167,8 +185,15 @@ DRIVER_ERROR Hbpl1::StartPage (JobAttrib
|
||||
DRIVER_ERROR err = NO_ERROR;
|
||||
|
||||
err = m_pHbpl1Wrapper->StartPage((void**)&m_pOutBuffer, &m_OutBuffSize);
|
||||
- err = sendBuffer(static_cast<const BYTE *>(m_pOutBuffer), m_OutBuffSize);
|
||||
- m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize);
|
||||
+ if (err != NO_ERROR)
|
||||
+ {
|
||||
+ return err;
|
||||
+ }
|
||||
+ if (m_pOutBuffer != NULL && m_OutBuffSize > 0)
|
||||
+ {
|
||||
+ err = sendBuffer(static_cast<const BYTE *>(m_pOutBuffer), m_OutBuffSize);
|
||||
+ m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize);
|
||||
+ }
|
||||
return err;
|
||||
}
|
||||
|
||||
@@ -183,28 +208,50 @@ DRIVER_ERROR Hbpl1::sendBlankBands()
|
||||
|
||||
DRIVER_ERROR Hbpl1::FormFeed ()
|
||||
{
|
||||
+ DRIVER_ERROR err = NO_ERROR;
|
||||
|
||||
if (0 != m_numScanLines && m_pbyStripData && 0 != m_nStripSize)
|
||||
- {
|
||||
- ++m_nBandCount;
|
||||
- m_pHbpl1Wrapper->Encapsulate(m_pbyStripData, m_nStripSize, m_nStripHeight, (void**)&m_pOutBuffer, &m_OutBuffSize);
|
||||
- sendBuffer(m_pOutBuffer, m_OutBuffSize);
|
||||
- memset(m_pbyStripData,0xFF,m_nStripSize);
|
||||
- }
|
||||
-
|
||||
- while(m_nBandCount < m_numStrips)
|
||||
- {
|
||||
- ++m_nBandCount;
|
||||
- m_pHbpl1Wrapper->Encapsulate(m_pbyStripData, m_nStripSize, m_nStripHeight, (void**)&m_pOutBuffer, &m_OutBuffSize);
|
||||
- sendBuffer(m_pOutBuffer, m_OutBuffSize);
|
||||
- }
|
||||
+ {
|
||||
+ ++m_nBandCount;
|
||||
+ err = m_pHbpl1Wrapper->Encapsulate(m_pbyStripData, m_nStripSize, m_nStripHeight, (void**)&m_pOutBuffer, &m_OutBuffSize);
|
||||
+ if (err != NO_ERROR)
|
||||
+ return err;
|
||||
+ if (m_pOutBuffer != NULL && m_OutBuffSize > 0)
|
||||
+ {
|
||||
+ err = sendBuffer(m_pOutBuffer, m_OutBuffSize);
|
||||
+ if (err != NO_ERROR)
|
||||
+ return err;
|
||||
+ }
|
||||
+ memset(m_pbyStripData,0xFF,m_nStripSize);
|
||||
+ }
|
||||
+
|
||||
+ while(m_nBandCount < m_numStrips)
|
||||
+ {
|
||||
+ ++m_nBandCount;
|
||||
+ err = m_pHbpl1Wrapper->Encapsulate(m_pbyStripData, m_nStripSize, m_nStripHeight, (void**)&m_pOutBuffer, &m_OutBuffSize);
|
||||
+ if (err != NO_ERROR)
|
||||
+ return err;
|
||||
+ if (m_pOutBuffer != NULL && m_OutBuffSize > 0)
|
||||
+ {
|
||||
+ err = sendBuffer(m_pOutBuffer, m_OutBuffSize);
|
||||
+ if (err != NO_ERROR)
|
||||
+ return err;
|
||||
+ }
|
||||
+ }
|
||||
|
||||
- m_pHbpl1Wrapper->EndPage((void**)&m_pOutBuffer, &m_OutBuffSize);
|
||||
- sendBuffer(m_pOutBuffer, m_OutBuffSize);
|
||||
+ err = m_pHbpl1Wrapper->EndPage((void**)&m_pOutBuffer, &m_OutBuffSize);
|
||||
+ if (err != NO_ERROR)
|
||||
+ return err;
|
||||
+ if (m_pOutBuffer != NULL && m_OutBuffSize > 0)
|
||||
+ {
|
||||
+ err = sendBuffer(m_pOutBuffer, m_OutBuffSize);
|
||||
+ if (err != NO_ERROR)
|
||||
+ return err;
|
||||
+ }
|
||||
m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer,m_OutBuffSize);
|
||||
- m_nBandCount = 0;
|
||||
+ m_nBandCount = 0;
|
||||
|
||||
- return NO_ERROR;
|
||||
+ return err;
|
||||
|
||||
}
|
||||
|
||||
diff -up hplip-3.21.2/prnt/hpcups/Hbpl1_Wrapper.cpp.CVE-2026-8631 hplip-3.21.2/prnt/hpcups/Hbpl1_Wrapper.cpp
|
||||
--- hplip-3.21.2/prnt/hpcups/Hbpl1_Wrapper.cpp.CVE-2026-8631 2021-02-15 00:55:21.000000000 +0100
|
||||
+++ hplip-3.21.2/prnt/hpcups/Hbpl1_Wrapper.cpp 2026-06-10 10:43:30.497695304 +0200
|
||||
@@ -77,19 +77,31 @@ void Hbpl1Wrapper::FreeStripBuffer(void)
|
||||
|
||||
DRIVER_ERROR Hbpl1Wrapper::StartJob(void **pOutBuffer, int *pOutBufferSize)
|
||||
{
|
||||
- DRIVER_ERROR err = NO_ERROR;
|
||||
-
|
||||
- m_pPCLmGenerator->StartJob(pOutBuffer,pOutBufferSize,false);
|
||||
- return err;
|
||||
+ int ret = m_pPCLmGenerator->StartJob(pOutBuffer,pOutBufferSize,false);
|
||||
+ if (ret != success)
|
||||
+ {
|
||||
+ if (pOutBuffer)
|
||||
+ *pOutBuffer = NULL;
|
||||
+ if (pOutBufferSize)
|
||||
+ *pOutBufferSize = 0;
|
||||
+ return SYSTEM_ERROR;
|
||||
+ }
|
||||
+ return NO_ERROR;
|
||||
}
|
||||
|
||||
|
||||
DRIVER_ERROR Hbpl1Wrapper::EndJob(void **pOutBuffer, int *pOutBufferSize)
|
||||
{
|
||||
- DRIVER_ERROR err = NO_ERROR;
|
||||
-
|
||||
- m_pPCLmGenerator->EndJob(pOutBuffer,pOutBufferSize);
|
||||
- return err;
|
||||
+ int ret = m_pPCLmGenerator->EndJob(pOutBuffer,pOutBufferSize);
|
||||
+ if (ret != success)
|
||||
+ {
|
||||
+ if (pOutBuffer)
|
||||
+ *pOutBuffer = NULL;
|
||||
+ if (pOutBufferSize)
|
||||
+ *pOutBufferSize = 0;
|
||||
+ return SYSTEM_ERROR;
|
||||
+ }
|
||||
+ return NO_ERROR;
|
||||
}
|
||||
|
||||
|
||||
@@ -173,8 +185,15 @@ DRIVER_ERROR Hbpl1Wrapper::StartPage(voi
|
||||
|
||||
PCLmPageContent.duplexDisposition = (duplexDispositionEnum)o_Hbpl1->m_JA.args_duplex_mode;
|
||||
|
||||
- m_pPCLmGenerator->StartPage(&PCLmSContent,true,pOutBuffer,pOutBufferSize);
|
||||
-
|
||||
+ int ret = m_pPCLmGenerator->StartPage(&PCLmSContent,true,pOutBuffer,pOutBufferSize);
|
||||
+ if (ret != success)
|
||||
+ {
|
||||
+ if (pOutBuffer)
|
||||
+ *pOutBuffer = NULL;
|
||||
+ if (pOutBufferSize)
|
||||
+ *pOutBufferSize = 0;
|
||||
+ return SYSTEM_ERROR;
|
||||
+ }
|
||||
|
||||
return err;
|
||||
}
|
||||
@@ -182,9 +201,16 @@ DRIVER_ERROR Hbpl1Wrapper::StartPage(voi
|
||||
|
||||
DRIVER_ERROR Hbpl1Wrapper::EndPage(void **pOutBuffer, int *pOutBufferSize)
|
||||
{
|
||||
- DRIVER_ERROR err = NO_ERROR;
|
||||
- m_pPCLmGenerator->EndPage(pOutBuffer, pOutBufferSize);
|
||||
- return err;
|
||||
+ int ret = m_pPCLmGenerator->EndPage(pOutBuffer, pOutBufferSize);
|
||||
+ if (ret != success)
|
||||
+ {
|
||||
+ if (pOutBuffer)
|
||||
+ *pOutBuffer = NULL;
|
||||
+ if (pOutBufferSize)
|
||||
+ *pOutBufferSize = 0;
|
||||
+ return SYSTEM_ERROR;
|
||||
+ }
|
||||
+ return NO_ERROR;
|
||||
}
|
||||
|
||||
|
||||
@@ -195,9 +221,16 @@ DRIVER_ERROR Hbpl1Wrapper::FormFeed()
|
||||
|
||||
DRIVER_ERROR Hbpl1Wrapper::Encapsulate (void *pInBuffer, int inBufferSize, int numLines, void **pOutBuffer, int *pOutBufferSize)
|
||||
{
|
||||
- DRIVER_ERROR err = NO_ERROR;
|
||||
- m_pPCLmGenerator->Encapsulate(pInBuffer, inBufferSize, numLines, pOutBuffer, pOutBufferSize);
|
||||
- return err;
|
||||
+ int ret = m_pPCLmGenerator->Encapsulate(pInBuffer, inBufferSize, numLines, pOutBuffer, pOutBufferSize);
|
||||
+ if (ret != success)
|
||||
+ {
|
||||
+ if (pOutBuffer)
|
||||
+ *pOutBuffer = NULL;
|
||||
+ if (pOutBufferSize)
|
||||
+ *pOutBufferSize = 0;
|
||||
+ return SYSTEM_ERROR;
|
||||
+ }
|
||||
+ return NO_ERROR;
|
||||
}
|
||||
|
||||
DRIVER_ERROR Hbpl1Wrapper::SkipLines (int iSkipLines)
|
||||
14
hplip.spec
14
hplip.spec
@ -7,7 +7,7 @@
|
||||
Summary: HP Linux Imaging and Printing Project
|
||||
Name: hplip
|
||||
Version: 3.21.2
|
||||
Release: 7%{?dist}
|
||||
Release: 8%{?dist}
|
||||
License: GPLv2+ and MIT and BSD and IJG and Public Domain and GPLv2+ with exceptions and ISC
|
||||
|
||||
Url: https://developers.hp.com/hp-linux-imaging-and-printing
|
||||
@ -191,6 +191,11 @@ Patch61: hplip-hpsetup-noscanjets.patch
|
||||
# via operating system command injection in Is_Process_Running()
|
||||
# https://redhat.atlassian.net/browse/RHEL-178365
|
||||
Patch62: hplip-CVE-2026-8632.patch
|
||||
# CVE-2026-8631 hplip: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups
|
||||
# https://redhat.atlassian.net/browse/RHEL-178728
|
||||
Patch63: hplip-CVE-2026-8631.patch
|
||||
# OSH fixes after CVE-2026-8631
|
||||
Patch64: hplip-CVE-2026-8631-osh.patch
|
||||
|
||||
%if 0%{?fedora} || 0%{?rhel} <= 8
|
||||
# mention hplip-gui if you want to have GUI
|
||||
@ -484,6 +489,10 @@ done
|
||||
%patch61 -p1 -b .hpsetup-noscanjets
|
||||
# CVE-2026-8632 - command injection in Is_Process_Running()
|
||||
%patch -P 62 -p1 -b .CVE-2026-8632
|
||||
# CVE-2026-8631 hplip: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups
|
||||
%patch -P 63 -p1 -b .CVE-2026-8631
|
||||
# OSH fixes after CVE-2026-8631
|
||||
%patch -P 64 -p1 -b .CVE-2026-8631-osh
|
||||
|
||||
%if 0%{?fedora} || 0%{?rhel} <= 8
|
||||
# mention hplip-gui should be installed if you want GUI
|
||||
@ -832,6 +841,9 @@ rm -f %{buildroot}%{_sysconfdir}/xdg/autostart/hplip-systray.desktop
|
||||
%config(noreplace) %{_sysconfdir}/sane.d/dll.d/hpaio
|
||||
|
||||
%changelog
|
||||
* Thu Jul 02 2026 Zdenek Dohnal <zdohnal@redhat.com> - 3.21.2-8
|
||||
- CVE-2026-8631 hplip: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups
|
||||
|
||||
* Thu Jul 02 2026 Zdenek Dohnal <zdohnal@redhat.com> - 3.21.2-7
|
||||
- CVE-2026-8632 hplip: HPLIP: Privilege escalation and arbitrary code execution
|
||||
via operating system command injection [rhel-9.9]
|
||||
|
||||
Loading…
Reference in New Issue
Block a user