diff --git a/hplip-CVE-2026-8631-osh.patch b/hplip-CVE-2026-8631-osh.patch new file mode 100644 index 0000000..226a570 --- /dev/null +++ b/hplip-CVE-2026-8631-osh.patch @@ -0,0 +1,92 @@ +diff -up hplip-3.21.2/prnt/hpcups/genPCLm.cpp.CVE-2026-8631-osh hplip-3.21.2/prnt/hpcups/genPCLm.cpp +--- hplip-3.21.2/prnt/hpcups/genPCLm.cpp.CVE-2026-8631-osh 2026-07-03 08:25:17.717888763 +0200 ++++ hplip-3.21.2/prnt/hpcups/genPCLm.cpp 2026-07-03 08:48:22.225130940 +0200 +@@ -1922,7 +1922,10 @@ int PCLmGenerator::Encapsulate(void *pI + int whiteStripLen=0; + if(!safe_mul_int_positive(thisHeight, currSourceWidth, &whiteStripLen) || + !safe_mul_int_positive(whiteStripLen, srcNumComponents, &whiteStripLen)) ++ { ++ free(newStripPtr); + return(errorOutAndCleanUp()); ++ } + bool whiteStrip=isWhiteStrip(pInBuffer, whiteStripLen); + if(DebugIt2) + { +@@ -1944,11 +1947,17 @@ int PCLmGenerator::Encapsulate(void *pI + ubyte whitePt=0xff; + size_t tmpStripSize=0; + if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize)) ++ { ++ free(newStripPtr); + return(errorOutAndCleanUp()); ++ } + + ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize); + if(!tmpStrip) ++ { ++ free(newStripPtr); + return(errorOutAndCleanUp()); ++ } + memset(tmpStrip,whitePt,tmpStripSize); + + +@@ -2016,7 +2025,10 @@ int PCLmGenerator::Encapsulate(void *pI + { + int sourceLen=0; + if(!safe_mul_int_positive(numLinesThisCall, scanlineWidth, &sourceLen)) ++ { ++ free(newStripPtr); + return(errorOutAndCleanUp()); ++ } + uint32 len=(uint32)sourceLen; + uLongf destSize=len; + +@@ -2025,12 +2037,18 @@ int PCLmGenerator::Encapsulate(void *pI + ubyte whitePt=0xff; + size_t tmpStripSize=0; + if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize)) ++ { ++ free(newStripPtr); + return(errorOutAndCleanUp()); ++ } + + // We need to inject a blank image-strip with a height==topMarginInPix + ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize); + if(!tmpStrip) ++ { ++ free(newStripPtr); + return(errorOutAndCleanUp()); ++ } + uLongf tmpDestSize=destSize; + memset(tmpStrip,whitePt,tmpStripSize); + +@@ -2079,20 +2097,29 @@ int PCLmGenerator::Encapsulate(void *pI + { + int sourceLen=0; + if(!safe_mul_int_positive(numLinesThisCall, scanlineWidth, &sourceLen)) ++ { ++ free(newStripPtr); + return(errorOutAndCleanUp()); ++ } + + if(firstStrip && topMarginInPix) + { + ubyte whitePt=0xff; + size_t tmpStripSize=0; + if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize)) ++ { ++ free(newStripPtr); + return(errorOutAndCleanUp()); ++ } + + // We need to inject a blank image-strip with a height==topMarginInPix + + ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize); + if(!tmpStrip) ++ { ++ free(newStripPtr); + return(errorOutAndCleanUp()); ++ } + memset(tmpStrip,whitePt,tmpStripSize); + + for(sint32 stripCntr=0; stripCntr + #include + #include ++#include ++#include ++#include ++#include + //#include "hpmud.h" + + #define _STRINGIZE(x) #x +@@ -54,6 +58,52 @@ enum UTILS_PLUGIN_LIBRARY_TYPE + }; + + ++/* Safe multiplication helpers - prevent integer overflow */ ++ ++/** ++ * safe_mul_size_t - Safely multiply two size_t values ++ * @a: First operand ++ * @b: Second operand ++ * @out: Output buffer for result ++ * Returns: true if multiplication succeeded, false if overflow detected ++ */ ++static inline bool safe_mul_size_t(size_t a, size_t b, size_t *out) ++{ ++ if (!out) ++ return false; ++ if (a == 0 || b == 0) ++ { ++ *out = 0; ++ return true; ++ } ++ if (a > ((size_t)-1) / b) ++ return false; ++ *out = a * b; ++ return true; ++} ++ ++/** ++ * safe_mul_int_positive - Safely multiply two positive integers ++ * @a: First operand (must be >= 0) ++ * @b: Second operand (must be >= 0) ++ * @out: Output buffer for result ++ * Returns: true if multiplication succeeded, false if negative input or overflow detected ++ */ ++static inline bool safe_mul_int_positive(int a, int b, int *out) ++{ ++ if (!out || a < 0 || b < 0) ++ return false; ++ if (a == 0 || b == 0) ++ { ++ *out = 0; ++ return true; ++ } ++ if (a > INT_MAX / b) ++ return false; ++ *out = a * b; ++ return true; ++} ++ + #ifdef __cplusplus + extern "C" { + #endif +diff -up hplip-3.21.2/prnt/hpcups/genPCLm.cpp.CVE-2026-8631 hplip-3.21.2/prnt/hpcups/genPCLm.cpp +--- hplip-3.21.2/prnt/hpcups/genPCLm.cpp.CVE-2026-8631 2026-06-10 10:43:30.459529186 +0200 ++++ hplip-3.21.2/prnt/hpcups/genPCLm.cpp 2026-06-10 10:43:30.497932359 +0200 +@@ -127,6 +127,7 @@ + #include + #include + #include ++#include + #include + //#include + +@@ -1674,7 +1675,12 @@ int PCLmGenerator::StartPage(PCLmPageSe + destColorSpace=PCLmPageContent->dstColorSpaceSpefication; + + // Calculate how large the output buffer needs to be based upon the page specifications +- int tmp_outBuffSize=mediaWidthInPixels*currStripHeight*dstNumComponents; ++ int tmp_outBuffSize=0; ++ if(!safe_mul_int_positive(mediaWidthInPixels,currStripHeight,&tmp_outBuffSize) || ++ !safe_mul_int_positive(tmp_outBuffSize,dstNumComponents,&tmp_outBuffSize)) ++ { ++ return(errorOutAndCleanUp()); ++ } + + if(tmp_outBuffSize>currOutBuffSize) + { +@@ -1742,7 +1748,14 @@ int PCLmGenerator::StartPage(PCLmPageSe + { + // We need to pad the scratchBuffer size to allow for compression expansion (RLE can create + // compressed segments that are slightly larger than the source. +- scratchBuffer=(ubyte*)malloc(currStripHeight*mediaWidthInPixels*srcNumComponents*2); ++ size_t scratchSize=0; ++ if(currStripHeight<=0 || mediaWidthInPixels<=0 || srcNumComponents<=0 || ++ !safe_mul_size_t((size_t)currStripHeight, (size_t)mediaWidthInPixels, &scratchSize) || ++ !safe_mul_size_t(scratchSize, (size_t)srcNumComponents, &scratchSize) || ++ !safe_mul_size_t(scratchSize, 2u, &scratchSize)) ++ return(errorOutAndCleanUp()); ++ ++ scratchBuffer=(ubyte*)malloc(scratchSize); + if(!scratchBuffer) + return(errorOutAndCleanUp()); + /*if(DebugIt2) +@@ -1798,7 +1811,9 @@ int PCLmGenerator::SkipLines(int iSkipL + int PCLmGenerator::Encapsulate(void *pInBuffer, int inBufferSize, int thisHeight, void **pOutBuffer, int *iOutBufferSize) + { + int result=0, numCompBytes; +- int scanlineWidth=mediaWidthInPixels*srcNumComponents; ++ int scanlineWidth=0; ++ if(!safe_mul_int_positive(mediaWidthInPixels, srcNumComponents, &scanlineWidth)) ++ return(errorOutAndCleanUp()); + int compSize; + // int numLinesThisCall=inBufferSize/(currSourceWidth*srcNumComponents); + int numLinesThisCall=thisHeight; +@@ -1888,7 +1903,8 @@ int PCLmGenerator::Encapsulate(void *pI + { + colorConvertSource(sourceColorSpace, grayScale, (ubyte*)localInBuffer, currSourceWidth, numLinesThisCall); + // Adjust the scanline width accordingly +- scanlineWidth = mediaWidthInPixels * dstNumComponents; ++ if(!safe_mul_int_positive(mediaWidthInPixels, dstNumComponents, &scanlineWidth)) ++ return(errorOutAndCleanUp()); + } + + if(leftMarginInPix) +@@ -1903,7 +1919,11 @@ int PCLmGenerator::Encapsulate(void *pI + } + + #ifdef SUPPORT_WHITE_STRIPS +- bool whiteStrip=isWhiteStrip(pInBuffer, thisHeight*currSourceWidth*srcNumComponents); ++ int whiteStripLen=0; ++ if(!safe_mul_int_positive(thisHeight, currSourceWidth, &whiteStripLen) || ++ !safe_mul_int_positive(whiteStripLen, srcNumComponents, &whiteStripLen)) ++ return(errorOutAndCleanUp()); ++ bool whiteStrip=isWhiteStrip(pInBuffer, whiteStripLen); + if(DebugIt2) + { + if(whiteStrip){ +@@ -1922,9 +1942,14 @@ int PCLmGenerator::Encapsulate(void *pI + if(firstStrip && topMarginInPix) + { + ubyte whitePt=0xff; +- +- ubyte *tmpStrip=(ubyte*)malloc(scanlineWidth*topMarginInPix); +- memset(tmpStrip,whitePt,scanlineWidth*topMarginInPix); ++ size_t tmpStripSize=0; ++ if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize)) ++ return(errorOutAndCleanUp()); ++ ++ ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize); ++ if(!tmpStrip) ++ return(errorOutAndCleanUp()); ++ memset(tmpStrip,whitePt,tmpStripSize); + + + for(sint32 stripCntr=0; stripCntruser_name); + if(DebugIt2) + { +- dbglog("Allocated zlib dest buffer of size %d\n",numLinesThisCall*scanlineWidth); ++ dbglog("Allocated zlib dest buffer of size %d\n",sourceLen); + dbglog("zlib compression return result=%d, compSize=%d\n",result,(int)destSize); + } + free(newStripPtr); +@@ -2030,12 +2063,12 @@ int PCLmGenerator::Encapsulate(void *pI + } + else + { +- result=compress((Bytef*)scratchBuffer, &destSize, (const Bytef*)localInBuffer, scanlineWidth*numLinesThisCall); ++ result=compress((Bytef*)scratchBuffer, &destSize, (const Bytef*)localInBuffer, (uLong)sourceLen); + if(DebugIt2) + writeOutputFile(destSize, scratchBuffer, m_pPCLmSSettings->user_name); + if(DebugIt2) + { +- dbglog("Allocated zlib dest buffer of size %d\n",numLinesThisCall*scanlineWidth); ++ dbglog("Allocated zlib dest buffer of size %d\n",sourceLen); + dbglog("zlib compression return result=%d, compSize=%d\n",result,(int)destSize); + } + } +@@ -2044,14 +2077,23 @@ int PCLmGenerator::Encapsulate(void *pI + + else if(currCompressionDisposition==compressRLE) + { ++ int sourceLen=0; ++ if(!safe_mul_int_positive(numLinesThisCall, scanlineWidth, &sourceLen)) ++ return(errorOutAndCleanUp()); ++ + if(firstStrip && topMarginInPix) + { + ubyte whitePt=0xff; ++ size_t tmpStripSize=0; ++ if(!safe_mul_size_t((size_t)scanlineWidth, (size_t)topMarginInPix, &tmpStripSize)) ++ return(errorOutAndCleanUp()); + + // We need to inject a blank image-strip with a height==topMarginInPix + +- ubyte *tmpStrip=(ubyte*)malloc(scanlineWidth*topMarginInPix); +- memset(tmpStrip,whitePt,scanlineWidth*topMarginInPix); ++ ubyte *tmpStrip=(ubyte*)malloc(tmpStripSize); ++ if(!tmpStrip) ++ return(errorOutAndCleanUp()); ++ memset(tmpStrip,whitePt,tmpStripSize); + + for(sint32 stripCntr=0; stripCntrStartJob((void**)&m_pOutBuffer, &m_OutBuffSize); +- err = sendBuffer(static_cast(m_pOutBuffer), m_OutBuffSize); +- m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize); ++ if (err != NO_ERROR) ++ { ++ return err; ++ } ++ if (m_pOutBuffer != NULL && m_OutBuffSize > 0) ++ { ++ err = sendBuffer(static_cast(m_pOutBuffer), m_OutBuffSize); ++ m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize); ++ if (err != NO_ERROR) ++ { ++ return err; ++ } ++ } + + if (m_PrintinGrayscale == ON){ //Grayscale = ON + m_ColorMode = COLORTYPE_BOTH; +@@ -156,8 +167,15 @@ DRIVER_ERROR Hbpl1::EndJob() + } + + err = m_pHbpl1Wrapper->EndJob((void**)&m_pOutBuffer, &m_OutBuffSize); +- err = sendBuffer(static_cast(m_pOutBuffer), m_OutBuffSize); +- m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize); ++ if (err != NO_ERROR) ++ { ++ return err; ++ } ++ if (m_pOutBuffer != NULL && m_OutBuffSize > 0) ++ { ++ err = sendBuffer(static_cast(m_pOutBuffer), m_OutBuffSize); ++ m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize); ++ } + return err; + } + +@@ -167,8 +185,15 @@ DRIVER_ERROR Hbpl1::StartPage (JobAttrib + DRIVER_ERROR err = NO_ERROR; + + err = m_pHbpl1Wrapper->StartPage((void**)&m_pOutBuffer, &m_OutBuffSize); +- err = sendBuffer(static_cast(m_pOutBuffer), m_OutBuffSize); +- m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize); ++ if (err != NO_ERROR) ++ { ++ return err; ++ } ++ if (m_pOutBuffer != NULL && m_OutBuffSize > 0) ++ { ++ err = sendBuffer(static_cast(m_pOutBuffer), m_OutBuffSize); ++ m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer, m_OutBuffSize); ++ } + return err; + } + +@@ -183,28 +208,50 @@ DRIVER_ERROR Hbpl1::sendBlankBands() + + DRIVER_ERROR Hbpl1::FormFeed () + { ++ DRIVER_ERROR err = NO_ERROR; + + if (0 != m_numScanLines && m_pbyStripData && 0 != m_nStripSize) +- { +- ++m_nBandCount; +- m_pHbpl1Wrapper->Encapsulate(m_pbyStripData, m_nStripSize, m_nStripHeight, (void**)&m_pOutBuffer, &m_OutBuffSize); +- sendBuffer(m_pOutBuffer, m_OutBuffSize); +- memset(m_pbyStripData,0xFF,m_nStripSize); +- } +- +- while(m_nBandCount < m_numStrips) +- { +- ++m_nBandCount; +- m_pHbpl1Wrapper->Encapsulate(m_pbyStripData, m_nStripSize, m_nStripHeight, (void**)&m_pOutBuffer, &m_OutBuffSize); +- sendBuffer(m_pOutBuffer, m_OutBuffSize); +- } ++ { ++ ++m_nBandCount; ++ err = m_pHbpl1Wrapper->Encapsulate(m_pbyStripData, m_nStripSize, m_nStripHeight, (void**)&m_pOutBuffer, &m_OutBuffSize); ++ if (err != NO_ERROR) ++ return err; ++ if (m_pOutBuffer != NULL && m_OutBuffSize > 0) ++ { ++ err = sendBuffer(m_pOutBuffer, m_OutBuffSize); ++ if (err != NO_ERROR) ++ return err; ++ } ++ memset(m_pbyStripData,0xFF,m_nStripSize); ++ } ++ ++ while(m_nBandCount < m_numStrips) ++ { ++ ++m_nBandCount; ++ err = m_pHbpl1Wrapper->Encapsulate(m_pbyStripData, m_nStripSize, m_nStripHeight, (void**)&m_pOutBuffer, &m_OutBuffSize); ++ if (err != NO_ERROR) ++ return err; ++ if (m_pOutBuffer != NULL && m_OutBuffSize > 0) ++ { ++ err = sendBuffer(m_pOutBuffer, m_OutBuffSize); ++ if (err != NO_ERROR) ++ return err; ++ } ++ } + +- m_pHbpl1Wrapper->EndPage((void**)&m_pOutBuffer, &m_OutBuffSize); +- sendBuffer(m_pOutBuffer, m_OutBuffSize); ++ err = m_pHbpl1Wrapper->EndPage((void**)&m_pOutBuffer, &m_OutBuffSize); ++ if (err != NO_ERROR) ++ return err; ++ if (m_pOutBuffer != NULL && m_OutBuffSize > 0) ++ { ++ err = sendBuffer(m_pOutBuffer, m_OutBuffSize); ++ if (err != NO_ERROR) ++ return err; ++ } + m_pHbpl1Wrapper->FreeBuffer(m_pOutBuffer,m_OutBuffSize); +- m_nBandCount = 0; ++ m_nBandCount = 0; + +- return NO_ERROR; ++ return err; + + } + +diff -up hplip-3.21.2/prnt/hpcups/Hbpl1_Wrapper.cpp.CVE-2026-8631 hplip-3.21.2/prnt/hpcups/Hbpl1_Wrapper.cpp +--- hplip-3.21.2/prnt/hpcups/Hbpl1_Wrapper.cpp.CVE-2026-8631 2021-02-15 00:55:21.000000000 +0100 ++++ hplip-3.21.2/prnt/hpcups/Hbpl1_Wrapper.cpp 2026-06-10 10:43:30.497695304 +0200 +@@ -77,19 +77,31 @@ void Hbpl1Wrapper::FreeStripBuffer(void) + + DRIVER_ERROR Hbpl1Wrapper::StartJob(void **pOutBuffer, int *pOutBufferSize) + { +- DRIVER_ERROR err = NO_ERROR; +- +- m_pPCLmGenerator->StartJob(pOutBuffer,pOutBufferSize,false); +- return err; ++ int ret = m_pPCLmGenerator->StartJob(pOutBuffer,pOutBufferSize,false); ++ if (ret != success) ++ { ++ if (pOutBuffer) ++ *pOutBuffer = NULL; ++ if (pOutBufferSize) ++ *pOutBufferSize = 0; ++ return SYSTEM_ERROR; ++ } ++ return NO_ERROR; + } + + + DRIVER_ERROR Hbpl1Wrapper::EndJob(void **pOutBuffer, int *pOutBufferSize) + { +- DRIVER_ERROR err = NO_ERROR; +- +- m_pPCLmGenerator->EndJob(pOutBuffer,pOutBufferSize); +- return err; ++ int ret = m_pPCLmGenerator->EndJob(pOutBuffer,pOutBufferSize); ++ if (ret != success) ++ { ++ if (pOutBuffer) ++ *pOutBuffer = NULL; ++ if (pOutBufferSize) ++ *pOutBufferSize = 0; ++ return SYSTEM_ERROR; ++ } ++ return NO_ERROR; + } + + +@@ -173,8 +185,15 @@ DRIVER_ERROR Hbpl1Wrapper::StartPage(voi + + PCLmPageContent.duplexDisposition = (duplexDispositionEnum)o_Hbpl1->m_JA.args_duplex_mode; + +- m_pPCLmGenerator->StartPage(&PCLmSContent,true,pOutBuffer,pOutBufferSize); +- ++ int ret = m_pPCLmGenerator->StartPage(&PCLmSContent,true,pOutBuffer,pOutBufferSize); ++ if (ret != success) ++ { ++ if (pOutBuffer) ++ *pOutBuffer = NULL; ++ if (pOutBufferSize) ++ *pOutBufferSize = 0; ++ return SYSTEM_ERROR; ++ } + + return err; + } +@@ -182,9 +201,16 @@ DRIVER_ERROR Hbpl1Wrapper::StartPage(voi + + DRIVER_ERROR Hbpl1Wrapper::EndPage(void **pOutBuffer, int *pOutBufferSize) + { +- DRIVER_ERROR err = NO_ERROR; +- m_pPCLmGenerator->EndPage(pOutBuffer, pOutBufferSize); +- return err; ++ int ret = m_pPCLmGenerator->EndPage(pOutBuffer, pOutBufferSize); ++ if (ret != success) ++ { ++ if (pOutBuffer) ++ *pOutBuffer = NULL; ++ if (pOutBufferSize) ++ *pOutBufferSize = 0; ++ return SYSTEM_ERROR; ++ } ++ return NO_ERROR; + } + + +@@ -195,9 +221,16 @@ DRIVER_ERROR Hbpl1Wrapper::FormFeed() + + DRIVER_ERROR Hbpl1Wrapper::Encapsulate (void *pInBuffer, int inBufferSize, int numLines, void **pOutBuffer, int *pOutBufferSize) + { +- DRIVER_ERROR err = NO_ERROR; +- m_pPCLmGenerator->Encapsulate(pInBuffer, inBufferSize, numLines, pOutBuffer, pOutBufferSize); +- return err; ++ int ret = m_pPCLmGenerator->Encapsulate(pInBuffer, inBufferSize, numLines, pOutBuffer, pOutBufferSize); ++ if (ret != success) ++ { ++ if (pOutBuffer) ++ *pOutBuffer = NULL; ++ if (pOutBufferSize) ++ *pOutBufferSize = 0; ++ return SYSTEM_ERROR; ++ } ++ return NO_ERROR; + } + + DRIVER_ERROR Hbpl1Wrapper::SkipLines (int iSkipLines) diff --git a/hplip.spec b/hplip.spec index 3d7000d..10f2307 100644 --- a/hplip.spec +++ b/hplip.spec @@ -7,7 +7,7 @@ Summary: HP Linux Imaging and Printing Project Name: hplip Version: 3.21.2 -Release: 7%{?dist} +Release: 8%{?dist} License: GPLv2+ and MIT and BSD and IJG and Public Domain and GPLv2+ with exceptions and ISC Url: https://developers.hp.com/hp-linux-imaging-and-printing @@ -191,6 +191,11 @@ Patch61: hplip-hpsetup-noscanjets.patch # via operating system command injection in Is_Process_Running() # https://redhat.atlassian.net/browse/RHEL-178365 Patch62: hplip-CVE-2026-8632.patch +# CVE-2026-8631 hplip: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups +# https://redhat.atlassian.net/browse/RHEL-178728 +Patch63: hplip-CVE-2026-8631.patch +# OSH fixes after CVE-2026-8631 +Patch64: hplip-CVE-2026-8631-osh.patch %if 0%{?fedora} || 0%{?rhel} <= 8 # mention hplip-gui if you want to have GUI @@ -484,6 +489,10 @@ done %patch61 -p1 -b .hpsetup-noscanjets # CVE-2026-8632 - command injection in Is_Process_Running() %patch -P 62 -p1 -b .CVE-2026-8632 +# CVE-2026-8631 hplip: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups +%patch -P 63 -p1 -b .CVE-2026-8631 +# OSH fixes after CVE-2026-8631 +%patch -P 64 -p1 -b .CVE-2026-8631-osh %if 0%{?fedora} || 0%{?rhel} <= 8 # mention hplip-gui should be installed if you want GUI @@ -832,6 +841,9 @@ rm -f %{buildroot}%{_sysconfdir}/xdg/autostart/hplip-systray.desktop %config(noreplace) %{_sysconfdir}/sane.d/dll.d/hpaio %changelog +* Thu Jul 02 2026 Zdenek Dohnal - 3.21.2-8 +- CVE-2026-8631 hplip: HPLIP: Arbitrary code execution and privilege escalation via integer overflow in hpcups + * Thu Jul 02 2026 Zdenek Dohnal - 3.21.2-7 - CVE-2026-8632 hplip: HPLIP: Privilege escalation and arbitrary code execution via operating system command injection [rhel-9.9]