CVE-2026-8631 hplip: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups

Resolves: RHEL-178728
This commit is contained in:
Zdenek Dohnal 2026-07-03 09:07:45 +02:00
parent 574e6df98e
commit 4045b63ef3
3 changed files with 600 additions and 1 deletions

View File

@ -0,0 +1,92 @@
diff -up hplip-3.21.2/prnt/hpcups/genPCLm.cpp.CVE-2026-8631-osh hplip-3.21.2/prnt/hpcups/genPCLm.cpp
--- hplip-3.21.2/prnt/hpcups/genPCLm.cpp.CVE-2026-8631-osh 2026-07-03 08:25:17.717888763 +0200
+++ hplip-3.21.2/prnt/hpcups/genPCLm.cpp 2026-07-03 08:48:22.225130940 +0200
@@ -1922,7 +1922,10 @@ int PCLmGenerator::Encapsulate(void *pI
int whiteStripLen=0;
if(!safe_mul_int_positive(thisHeight, currSourceWidth, &whiteStripLen) ||
!safe_mul_int_positive(whiteStripLen, srcNumComponents, &whiteStripLen))
+ {
+ free(newStripPtr);
return(errorOutAndCleanUp());
+ }
bool whiteStrip=isWhiteStrip(pInBuffer, whiteStripLen);
if(DebugIt2)
{
@@ -1944,11 +1947,17 @@ int PCLmGenerator::Encapsulate(void *pI
ubyte whitePt=0xff;
size_t tmpStripSize=0;
if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize))
+ {
+ free(newStripPtr);
return(errorOutAndCleanUp());
+ }
ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize);
if(!tmpStrip)
+ {
+ free(newStripPtr);
return(errorOutAndCleanUp());
+ }
memset(tmpStrip,whitePt,tmpStripSize);
@@ -2016,7 +2025,10 @@ int PCLmGenerator::Encapsulate(void *pI
{
int sourceLen=0;
if(!safe_mul_int_positive(numLinesThisCall, scanlineWidth, &sourceLen))
+ {
+ free(newStripPtr);
return(errorOutAndCleanUp());
+ }
uint32 len=(uint32)sourceLen;
uLongf destSize=len;
@@ -2025,12 +2037,18 @@ int PCLmGenerator::Encapsulate(void *pI
ubyte whitePt=0xff;
size_t tmpStripSize=0;
if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize))
+ {
+ free(newStripPtr);
return(errorOutAndCleanUp());
+ }
// We need to inject a blank image-strip with a height==topMarginInPix
ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize);
if(!tmpStrip)
+ {
+ free(newStripPtr);
return(errorOutAndCleanUp());
+ }
uLongf tmpDestSize=destSize;
memset(tmpStrip,whitePt,tmpStripSize);
@@ -2079,20 +2097,29 @@ int PCLmGenerator::Encapsulate(void *pI
{
int sourceLen=0;
if(!safe_mul_int_positive(numLinesThisCall, scanlineWidth, &sourceLen))
+ {
+ free(newStripPtr);
return(errorOutAndCleanUp());
+ }
if(firstStrip && topMarginInPix)
{
ubyte whitePt=0xff;
size_t tmpStripSize=0;
if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize))
+ {
+ free(newStripPtr);
return(errorOutAndCleanUp());
+ }
// We need to inject a blank image-strip with a height==topMarginInPix
ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize);
if(!tmpStrip)
+ {
+ free(newStripPtr);
return(errorOutAndCleanUp());
+ }
memset(tmpStrip,whitePt,tmpStripSize);
for(sint32 stripCntr=0; stripCntr<numFullInjectedStrips;stripCntr++)

495
hplip-CVE-2026-8631.patch Normal file
View File

@ -0,0 +1,495 @@
diff -up hplip-3.21.2/common/utils.h.CVE-2026-8631 hplip-3.21.2/common/utils.h
--- hplip-3.21.2/common/utils.h.CVE-2026-8631 2021-02-15 00:55:21.000000000 +0100
+++ hplip-3.21.2/common/utils.h 2026-06-10 10:43:30.497271871 +0200
@@ -4,6 +4,10 @@
#include <stdio.h>
#include <stdarg.h>
#include <syslog.h>
+#include <stdint.h>
+#include <limits.h>
+#include <stdbool.h>
+#include <stddef.h>
//#include "hpmud.h"
#define _STRINGIZE(x) #x
@@ -54,6 +58,52 @@ enum UTILS_PLUGIN_LIBRARY_TYPE
};
+/* Safe multiplication helpers - prevent integer overflow */
+
+/**
+ * safe_mul_size_t - Safely multiply two size_t values
+ * @a: First operand
+ * @b: Second operand
+ * @out: Output buffer for result
+ * Returns: true if multiplication succeeded, false if overflow detected
+ */
+static inline bool safe_mul_size_t(size_t a, size_t b, size_t *out)
+{
+ if (!out)
+ return false;
+ if (a == 0 || b == 0)
+ {
+ *out = 0;
+ return true;
+ }
+ if (a > ((size_t)-1) / b)
+ return false;
+ *out = a * b;
+ return true;
+}
+
+/**
+ * safe_mul_int_positive - Safely multiply two positive integers
+ * @a: First operand (must be >= 0)
+ * @b: Second operand (must be >= 0)
+ * @out: Output buffer for result
+ * Returns: true if multiplication succeeded, false if negative input or overflow detected
+ */
+static inline bool safe_mul_int_positive(int a, int b, int *out)
+{
+ if (!out || a < 0 || b < 0)
+ return false;
+ if (a == 0 || b == 0)
+ {
+ *out = 0;
+ return true;
+ }
+ if (a > INT_MAX / b)
+ return false;
+ *out = a * b;
+ return true;
+}
+
#ifdef __cplusplus
extern "C" {
#endif
diff -up hplip-3.21.2/prnt/hpcups/genPCLm.cpp.CVE-2026-8631 hplip-3.21.2/prnt/hpcups/genPCLm.cpp
--- hplip-3.21.2/prnt/hpcups/genPCLm.cpp.CVE-2026-8631 2026-06-10 10:43:30.459529186 +0200
+++ hplip-3.21.2/prnt/hpcups/genPCLm.cpp 2026-06-10 10:43:30.497932359 +0200
@@ -127,6 +127,7 @@
#include <fcntl.h>
#include <assert.h>
#include <math.h>
+#include <limits.h>
#include <zlib.h>
//#include <unistd.h>
@@ -1674,7 +1675,12 @@ int PCLmGenerator::StartPage(PCLmPageSe
destColorSpace=PCLmPageContent->dstColorSpaceSpefication;
// Calculate how large the output buffer needs to be based upon the page specifications
- int tmp_outBuffSize=mediaWidthInPixels*currStripHeight*dstNumComponents;
+ int tmp_outBuffSize=0;
+ if(!safe_mul_int_positive(mediaWidthInPixels,currStripHeight,&tmp_outBuffSize) ||
+ !safe_mul_int_positive(tmp_outBuffSize,dstNumComponents,&tmp_outBuffSize))
+ {
+ return(errorOutAndCleanUp());
+ }
if(tmp_outBuffSize>currOutBuffSize)
{
@@ -1742,7 +1748,14 @@ int PCLmGenerator::StartPage(PCLmPageSe
{
// We need to pad the scratchBuffer size to allow for compression expansion (RLE can create
// compressed segments that are slightly larger than the source.
- scratchBuffer=(ubyte*)malloc(currStripHeight*mediaWidthInPixels*srcNumComponents*2);
+ size_t scratchSize=0;
+ if(currStripHeight<=0 || mediaWidthInPixels<=0 || srcNumComponents<=0 ||
+ !safe_mul_size_t((size_t)currStripHeight, (size_t)mediaWidthInPixels, &scratchSize) ||
+ !safe_mul_size_t(scratchSize, (size_t)srcNumComponents, &scratchSize) ||
+ !safe_mul_size_t(scratchSize, 2u, &scratchSize))
+ return(errorOutAndCleanUp());
+
+ scratchBuffer=(ubyte*)malloc(scratchSize);
if(!scratchBuffer)
return(errorOutAndCleanUp());
/*if(DebugIt2)
@@ -1798,7 +1811,9 @@ int PCLmGenerator::SkipLines(int iSkipL
int PCLmGenerator::Encapsulate(void *pInBuffer, int inBufferSize, int thisHeight, void **pOutBuffer, int *iOutBufferSize)
{
int result=0, numCompBytes;
- int scanlineWidth=mediaWidthInPixels*srcNumComponents;
+ int scanlineWidth=0;
+ if(!safe_mul_int_positive(mediaWidthInPixels, srcNumComponents, &scanlineWidth))
+ return(errorOutAndCleanUp());
int compSize;
// int numLinesThisCall=inBufferSize/(currSourceWidth*srcNumComponents);
int numLinesThisCall=thisHeight;
@@ -1888,7 +1903,8 @@ int PCLmGenerator::Encapsulate(void *pI
{
colorConvertSource(sourceColorSpace, grayScale, (ubyte*)localInBuffer, currSourceWidth, numLinesThisCall);
// Adjust the scanline width accordingly
- scanlineWidth = mediaWidthInPixels * dstNumComponents;
+ if(!safe_mul_int_positive(mediaWidthInPixels, dstNumComponents, &scanlineWidth))
+ return(errorOutAndCleanUp());
}
if(leftMarginInPix)
@@ -1903,7 +1919,11 @@ int PCLmGenerator::Encapsulate(void *pI
}
#ifdef SUPPORT_WHITE_STRIPS
- bool whiteStrip=isWhiteStrip(pInBuffer, thisHeight*currSourceWidth*srcNumComponents);
+ int whiteStripLen=0;
+ if(!safe_mul_int_positive(thisHeight, currSourceWidth, &whiteStripLen) ||
+ !safe_mul_int_positive(whiteStripLen, srcNumComponents, &whiteStripLen))
+ return(errorOutAndCleanUp());
+ bool whiteStrip=isWhiteStrip(pInBuffer, whiteStripLen);
if(DebugIt2)
{
if(whiteStrip){
@@ -1922,9 +1942,14 @@ int PCLmGenerator::Encapsulate(void *pI
if(firstStrip && topMarginInPix)
{
ubyte whitePt=0xff;
-
- ubyte *tmpStrip=(ubyte*)malloc(scanlineWidth*topMarginInPix);
- memset(tmpStrip,whitePt,scanlineWidth*topMarginInPix);
+ size_t tmpStripSize=0;
+ if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize))
+ return(errorOutAndCleanUp());
+
+ ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize);
+ if(!tmpStrip)
+ return(errorOutAndCleanUp());
+ memset(tmpStrip,whitePt,tmpStripSize);
for(sint32 stripCntr=0; stripCntr<numFullInjectedStrips;stripCntr++)
@@ -1989,17 +2014,25 @@ int PCLmGenerator::Encapsulate(void *pI
}
else if(currCompressionDisposition==compressFlate)
{
- uint32 len=numLinesThisCall*scanlineWidth;
+ int sourceLen=0;
+ if(!safe_mul_int_positive(numLinesThisCall, scanlineWidth, &sourceLen))
+ return(errorOutAndCleanUp());
+ uint32 len=(uint32)sourceLen;
uLongf destSize=len;
if(firstStrip && topMarginInPix)
{
ubyte whitePt=0xff;
+ size_t tmpStripSize=0;
+ if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize))
+ return(errorOutAndCleanUp());
// We need to inject a blank image-strip with a height==topMarginInPix
- ubyte *tmpStrip=(ubyte*)malloc(scanlineWidth*topMarginInPix);
+ ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize);
+ if(!tmpStrip)
+ return(errorOutAndCleanUp());
uLongf tmpDestSize=destSize;
- memset(tmpStrip,whitePt,scanlineWidth*topMarginInPix);
+ memset(tmpStrip,whitePt,tmpStripSize);
for(sint32 stripCntr=0; stripCntr<numFullInjectedStrips;stripCntr++)
{
@@ -2017,12 +2050,12 @@ int PCLmGenerator::Encapsulate(void *pI
if(newStripPtr)
{
- result=compress((Bytef*)scratchBuffer,&destSize,(const Bytef*)newStripPtr,scanlineWidth*numLinesThisCall);
+ result=compress((Bytef*)scratchBuffer,&destSize,(const Bytef*)newStripPtr,(uLong)sourceLen);
if(DebugIt2)
writeOutputFile(destSize, scratchBuffer, m_pPCLmSSettings->user_name);
if(DebugIt2)
{
- dbglog("Allocated zlib dest buffer of size %d\n",numLinesThisCall*scanlineWidth);
+ dbglog("Allocated zlib dest buffer of size %d\n",sourceLen);
dbglog("zlib compression return result=%d, compSize=%d\n",result,(int)destSize);
}
free(newStripPtr);
@@ -2030,12 +2063,12 @@ int PCLmGenerator::Encapsulate(void *pI
}
else
{
- result=compress((Bytef*)scratchBuffer, &destSize, (const Bytef*)localInBuffer, scanlineWidth*numLinesThisCall);
+ result=compress((Bytef*)scratchBuffer, &destSize, (const Bytef*)localInBuffer, (uLong)sourceLen);
if(DebugIt2)
writeOutputFile(destSize, scratchBuffer, m_pPCLmSSettings->user_name);
if(DebugIt2)
{
- dbglog("Allocated zlib dest buffer of size %d\n",numLinesThisCall*scanlineWidth);
+ dbglog("Allocated zlib dest buffer of size %d\n",sourceLen);
dbglog("zlib compression return result=%d, compSize=%d\n",result,(int)destSize);
}
}
@@ -2044,14 +2077,23 @@ int PCLmGenerator::Encapsulate(void *pI
else if(currCompressionDisposition==compressRLE)
{
+ int sourceLen=0;
+ if(!safe_mul_int_positive(numLinesThisCall, scanlineWidth, &sourceLen))
+ return(errorOutAndCleanUp());
+
if(firstStrip && topMarginInPix)
{
ubyte whitePt=0xff;
+ size_t tmpStripSize=0;
+ if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize))
+ return(errorOutAndCleanUp());
// We need to inject a blank image-strip with a height==topMarginInPix
- ubyte *tmpStrip=(ubyte*)malloc(scanlineWidth*topMarginInPix);
- memset(tmpStrip,whitePt,scanlineWidth*topMarginInPix);
+ ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize);
+ if(!tmpStrip)
+ return(errorOutAndCleanUp());
+ memset(tmpStrip,whitePt,tmpStripSize);
for(sint32 stripCntr=0; stripCntr<numFullInjectedStrips;stripCntr++)
{
@@ -2071,16 +2113,16 @@ int PCLmGenerator::Encapsulate(void *pI
if(newStripPtr)
{
- compSize=HPRunLen_Encode((ubyte*)newStripPtr, scratchBuffer, scanlineWidth*numLinesThisCall);
+ compSize=HPRunLen_Encode((ubyte*)newStripPtr, scratchBuffer, sourceLen);
free(newStripPtr);
newStripPtr = NULL;
}
else
- compSize=HPRunLen_Encode((ubyte*)localInBuffer, scratchBuffer, scanlineWidth*numLinesThisCall);
+ compSize=HPRunLen_Encode((ubyte*)localInBuffer, scratchBuffer, sourceLen);
if(DebugIt2)
{
- dbglog("Allocated rle dest buffer of size %d\n",numLinesThisCall*scanlineWidth);
+ dbglog("Allocated rle dest buffer of size %d\n",sourceLen);
dbglog("rle compression return size=%d=%d\n",result,(int)compSize);
}
injectRLEStrip(scratchBuffer, compSize, mediaWidthInPixels, numLinesThisCall, destColorSpace, whiteStrip);
diff -up hplip-3.21.2/prnt/hpcups/Hbpl1.cpp.CVE-2026-8631 hplip-3.21.2/prnt/hpcups/Hbpl1.cpp
--- hplip-3.21.2/prnt/hpcups/Hbpl1.cpp.CVE-2026-8631 2021-02-15 00:55:21.000000000 +0100
+++ hplip-3.21.2/prnt/hpcups/Hbpl1.cpp 2026-06-10 10:50:47.505618389 +0200
@@ -130,8 +130,19 @@ DRIVER_ERROR Hbpl1::StartJob(SystemServi
m_PrintinGrayscale = m_JA.integer_values[3]; // cupsInterger3 value
m_pSystemServices = pSystemServices; //Reset and UEL not required
err = m_pHbpl1Wrapper->StartJob((void**)&m_pOutBuffer, &m_OutBuffSize);
- err = sendBuffer(static_cast<const BYTE *>(m_pOutBuffer), m_OutBuffSize);
- m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize);
+ if (err != NO_ERROR)
+ {
+ return err;
+ }
+ if (m_pOutBuffer != NULL && m_OutBuffSize > 0)
+ {
+ err = sendBuffer(static_cast<const BYTE *>(m_pOutBuffer), m_OutBuffSize);
+ m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize);
+ if (err != NO_ERROR)
+ {
+ return err;
+ }
+ }
if (m_PrintinGrayscale == ON){ //Grayscale = ON
m_ColorMode = COLORTYPE_BOTH;
@@ -156,8 +167,15 @@ DRIVER_ERROR Hbpl1::EndJob()
}
err = m_pHbpl1Wrapper->EndJob((void**)&m_pOutBuffer, &m_OutBuffSize);
- err = sendBuffer(static_cast<const BYTE *>(m_pOutBuffer), m_OutBuffSize);
- m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize);
+ if (err != NO_ERROR)
+ {
+ return err;
+ }
+ if (m_pOutBuffer != NULL && m_OutBuffSize > 0)
+ {
+ err = sendBuffer(static_cast<const BYTE *>(m_pOutBuffer), m_OutBuffSize);
+ m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize);
+ }
return err;
}
@@ -167,8 +185,15 @@ DRIVER_ERROR Hbpl1::StartPage (JobAttrib
DRIVER_ERROR err = NO_ERROR;
err = m_pHbpl1Wrapper->StartPage((void**)&m_pOutBuffer, &m_OutBuffSize);
- err = sendBuffer(static_cast<const BYTE *>(m_pOutBuffer), m_OutBuffSize);
- m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize);
+ if (err != NO_ERROR)
+ {
+ return err;
+ }
+ if (m_pOutBuffer != NULL && m_OutBuffSize > 0)
+ {
+ err = sendBuffer(static_cast<const BYTE *>(m_pOutBuffer), m_OutBuffSize);
+ m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize);
+ }
return err;
}
@@ -183,28 +208,50 @@ DRIVER_ERROR Hbpl1::sendBlankBands()
DRIVER_ERROR Hbpl1::FormFeed ()
{
+ DRIVER_ERROR err = NO_ERROR;
if (0 != m_numScanLines && m_pbyStripData && 0 != m_nStripSize)
- {
- ++m_nBandCount;
- m_pHbpl1Wrapper->Encapsulate(m_pbyStripData, m_nStripSize, m_nStripHeight, (void**)&m_pOutBuffer, &m_OutBuffSize);
- sendBuffer(m_pOutBuffer, m_OutBuffSize);
- memset(m_pbyStripData,0xFF,m_nStripSize);
- }
-
- while(m_nBandCount < m_numStrips)
- {
- ++m_nBandCount;
- m_pHbpl1Wrapper->Encapsulate(m_pbyStripData, m_nStripSize, m_nStripHeight, (void**)&m_pOutBuffer, &m_OutBuffSize);
- sendBuffer(m_pOutBuffer, m_OutBuffSize);
- }
+ {
+ ++m_nBandCount;
+ err = m_pHbpl1Wrapper->Encapsulate(m_pbyStripData, m_nStripSize, m_nStripHeight, (void**)&m_pOutBuffer, &m_OutBuffSize);
+ if (err != NO_ERROR)
+ return err;
+ if (m_pOutBuffer != NULL && m_OutBuffSize > 0)
+ {
+ err = sendBuffer(m_pOutBuffer, m_OutBuffSize);
+ if (err != NO_ERROR)
+ return err;
+ }
+ memset(m_pbyStripData,0xFF,m_nStripSize);
+ }
+
+ while(m_nBandCount < m_numStrips)
+ {
+ ++m_nBandCount;
+ err = m_pHbpl1Wrapper->Encapsulate(m_pbyStripData, m_nStripSize, m_nStripHeight, (void**)&m_pOutBuffer, &m_OutBuffSize);
+ if (err != NO_ERROR)
+ return err;
+ if (m_pOutBuffer != NULL && m_OutBuffSize > 0)
+ {
+ err = sendBuffer(m_pOutBuffer, m_OutBuffSize);
+ if (err != NO_ERROR)
+ return err;
+ }
+ }
- m_pHbpl1Wrapper->EndPage((void**)&m_pOutBuffer, &m_OutBuffSize);
- sendBuffer(m_pOutBuffer, m_OutBuffSize);
+ err = m_pHbpl1Wrapper->EndPage((void**)&m_pOutBuffer, &m_OutBuffSize);
+ if (err != NO_ERROR)
+ return err;
+ if (m_pOutBuffer != NULL && m_OutBuffSize > 0)
+ {
+ err = sendBuffer(m_pOutBuffer, m_OutBuffSize);
+ if (err != NO_ERROR)
+ return err;
+ }
m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer,m_OutBuffSize);
- m_nBandCount = 0;
+ m_nBandCount = 0;
- return NO_ERROR;
+ return err;
}
diff -up hplip-3.21.2/prnt/hpcups/Hbpl1_Wrapper.cpp.CVE-2026-8631 hplip-3.21.2/prnt/hpcups/Hbpl1_Wrapper.cpp
--- hplip-3.21.2/prnt/hpcups/Hbpl1_Wrapper.cpp.CVE-2026-8631 2021-02-15 00:55:21.000000000 +0100
+++ hplip-3.21.2/prnt/hpcups/Hbpl1_Wrapper.cpp 2026-06-10 10:43:30.497695304 +0200
@@ -77,19 +77,31 @@ void Hbpl1Wrapper::FreeStripBuffer(void)
DRIVER_ERROR Hbpl1Wrapper::StartJob(void **pOutBuffer, int *pOutBufferSize)
{
- DRIVER_ERROR err = NO_ERROR;
-
- m_pPCLmGenerator->StartJob(pOutBuffer,pOutBufferSize,false);
- return err;
+ int ret = m_pPCLmGenerator->StartJob(pOutBuffer,pOutBufferSize,false);
+ if (ret != success)
+ {
+ if (pOutBuffer)
+ *pOutBuffer = NULL;
+ if (pOutBufferSize)
+ *pOutBufferSize = 0;
+ return SYSTEM_ERROR;
+ }
+ return NO_ERROR;
}
DRIVER_ERROR Hbpl1Wrapper::EndJob(void **pOutBuffer, int *pOutBufferSize)
{
- DRIVER_ERROR err = NO_ERROR;
-
- m_pPCLmGenerator->EndJob(pOutBuffer,pOutBufferSize);
- return err;
+ int ret = m_pPCLmGenerator->EndJob(pOutBuffer,pOutBufferSize);
+ if (ret != success)
+ {
+ if (pOutBuffer)
+ *pOutBuffer = NULL;
+ if (pOutBufferSize)
+ *pOutBufferSize = 0;
+ return SYSTEM_ERROR;
+ }
+ return NO_ERROR;
}
@@ -173,8 +185,15 @@ DRIVER_ERROR Hbpl1Wrapper::StartPage(voi
PCLmPageContent.duplexDisposition = (duplexDispositionEnum)o_Hbpl1->m_JA.args_duplex_mode;
- m_pPCLmGenerator->StartPage(&PCLmSContent,true,pOutBuffer,pOutBufferSize);
-
+ int ret = m_pPCLmGenerator->StartPage(&PCLmSContent,true,pOutBuffer,pOutBufferSize);
+ if (ret != success)
+ {
+ if (pOutBuffer)
+ *pOutBuffer = NULL;
+ if (pOutBufferSize)
+ *pOutBufferSize = 0;
+ return SYSTEM_ERROR;
+ }
return err;
}
@@ -182,9 +201,16 @@ DRIVER_ERROR Hbpl1Wrapper::StartPage(voi
DRIVER_ERROR Hbpl1Wrapper::EndPage(void **pOutBuffer, int *pOutBufferSize)
{
- DRIVER_ERROR err = NO_ERROR;
- m_pPCLmGenerator->EndPage(pOutBuffer, pOutBufferSize);
- return err;
+ int ret = m_pPCLmGenerator->EndPage(pOutBuffer, pOutBufferSize);
+ if (ret != success)
+ {
+ if (pOutBuffer)
+ *pOutBuffer = NULL;
+ if (pOutBufferSize)
+ *pOutBufferSize = 0;
+ return SYSTEM_ERROR;
+ }
+ return NO_ERROR;
}
@@ -195,9 +221,16 @@ DRIVER_ERROR Hbpl1Wrapper::FormFeed()
DRIVER_ERROR Hbpl1Wrapper::Encapsulate (void *pInBuffer, int inBufferSize, int numLines, void **pOutBuffer, int *pOutBufferSize)
{
- DRIVER_ERROR err = NO_ERROR;
- m_pPCLmGenerator->Encapsulate(pInBuffer, inBufferSize, numLines, pOutBuffer, pOutBufferSize);
- return err;
+ int ret = m_pPCLmGenerator->Encapsulate(pInBuffer, inBufferSize, numLines, pOutBuffer, pOutBufferSize);
+ if (ret != success)
+ {
+ if (pOutBuffer)
+ *pOutBuffer = NULL;
+ if (pOutBufferSize)
+ *pOutBufferSize = 0;
+ return SYSTEM_ERROR;
+ }
+ return NO_ERROR;
}
DRIVER_ERROR Hbpl1Wrapper::SkipLines (int iSkipLines)

View File

@ -7,7 +7,7 @@
Summary: HP Linux Imaging and Printing Project
Name: hplip
Version: 3.21.2
Release: 7%{?dist}
Release: 8%{?dist}
License: GPLv2+ and MIT and BSD and IJG and Public Domain and GPLv2+ with exceptions and ISC
Url: https://developers.hp.com/hp-linux-imaging-and-printing
@ -191,6 +191,11 @@ Patch61: hplip-hpsetup-noscanjets.patch
# via operating system command injection in Is_Process_Running()
# https://redhat.atlassian.net/browse/RHEL-178365
Patch62: hplip-CVE-2026-8632.patch
# CVE-2026-8631 hplip: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups
# https://redhat.atlassian.net/browse/RHEL-178728
Patch63: hplip-CVE-2026-8631.patch
# OSH fixes after CVE-2026-8631
Patch64: hplip-CVE-2026-8631-osh.patch
%if 0%{?fedora} || 0%{?rhel} <= 8
# mention hplip-gui if you want to have GUI
@ -484,6 +489,10 @@ done
%patch61 -p1 -b .hpsetup-noscanjets
# CVE-2026-8632 - command injection in Is_Process_Running()
%patch -P 62 -p1 -b .CVE-2026-8632
# CVE-2026-8631 hplip: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups
%patch -P 63 -p1 -b .CVE-2026-8631
# OSH fixes after CVE-2026-8631
%patch -P 64 -p1 -b .CVE-2026-8631-osh
%if 0%{?fedora} || 0%{?rhel} <= 8
# mention hplip-gui should be installed if you want GUI
@ -832,6 +841,9 @@ rm -f %{buildroot}%{_sysconfdir}/xdg/autostart/hplip-systray.desktop
%config(noreplace) %{_sysconfdir}/sane.d/dll.d/hpaio
%changelog
* Thu Jul 02 2026 Zdenek Dohnal <zdohnal@redhat.com> - 3.21.2-8
- CVE-2026-8631 hplip: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups
* Thu Jul 02 2026 Zdenek Dohnal <zdohnal@redhat.com> - 3.21.2-7
- CVE-2026-8632 hplip: HPLIP: Privilege escalation and arbitrary code execution
via operating system command injection [rhel-9.9]